Security Advisory
CVE-2014-0476
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.