Advisories ยป MGASA-2014-0249

Updated chkrootkit packages fix CVE-2014-0476 and a false positive

Publication date: 04 Jun 2014
Modification date: 04 Jun 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-0476

Description

Updated chkrootkit package fixes security vulnerability:

The chkrootkit script contains a flaw that allows a local attacker to create
an executable in /tmp that will be run by the user running chkrootkit (usually
root), allowing the attacker to escalate privileges (CVE-2014-0476).

The Mageia 3 update also eliminates the false positive identification of a
rootkit in /sbin/init (mga#6699).
                

References

SRPMS

4/core

3/core