Thomas Stangner discovered that chkrootkit incorrectly quoted certain values. A local attacker could use this issue to execute arbitrary code when chkrootkit is run and gain root privileges.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "chkrootkit", "binary_version": "0.49-4.1ubuntu1.14.04.1" } ] }
{ "cves": [ { "severity": [ { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2014-0476" } ], "ecosystem": "Ubuntu:14.04:LTS" }