Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
chkrootkit‘slapper()’权限许可和访问控制漏洞
Vulnerability Description
chkrootkit是软件开发者Nelson Murilo所研发的一套用于在Linux系统下查找检测rootkit后门的工具。 chkrootkit 0.50之前版本的‘slapper’函数中存在安全漏洞,该漏洞源于程序没有正确引用文件路径。本地攻击者可借助可执行的Trojan horse利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A