GLSA Advocate

Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Sep 17, 2017 7:26 pm Post subject: [ GLSA 201709-05 ] chkrootkit |
|
|
Gentoo Linux Security Advisory
Title: chkrootkit: Local privilege escalation (GLSA 201709-05)
Severity: high
Exploitable: local
Date: 2017-09-17
Bug(s): #512356
ID: 201709-05
Synopsis
A vulnerability in chkrootkit may allow local users to gain root
privileges.
Background
chkrootkit is a tool to locally check for signs of a rootkit.
Affected Packages
Package: app-forensics/chkrootkit
Vulnerable: < 0.50
Unaffected: >= 0.50
Architectures: All supported architectures
Description
When /tmp is mounted without the noexec option chkrootkit will execute
files in /tmp with root privileges.
Impact
A local attacker could possibly execute arbitrary code with root
privileges.
Workaround
Users should mount /tmp with noexec option.
Resolution
All chkrootkit users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-forensics/chkrootkit-0.50"
|
References
CVE-2014-0476
|
|