Updated chkrootkit packages fix CVE-2014-0476 and a false positive
Publication date: 04 Jun 2014Modification date: 04 Jun 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-0476
Description
Updated chkrootkit package fixes security vulnerability: The chkrootkit script contains a flaw that allows a local attacker to create an executable in /tmp that will be run by the user running chkrootkit (usually root), allowing the attacker to escalate privileges (CVE-2014-0476). The Mageia 3 update also eliminates the false positive identification of a rootkit in /sbin/init (mga#6699).
References
SRPMS
4/core
- chkrootkit-0.49-8.1.mga4
3/core
- chkrootkit-0.49-6.1.mga3