Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0476

29
FAUCET Score

CVE-2014-0476 describes a local privilege escalation vulnerability in chkrootkit versions prior to 0.50, affecting Canonical Ubuntu Linux and chkrootkit itself. This flaw, stemming from improper quoting of file paths in the 'slapper' function, allows local users to execute arbitrary code via a Trojan horse executable, provided the /tmp directory is not mounted with the noexec option. With a CVSS score of 3.7 (AV:L/AC:H/Au:N/C:P/I:P/A:P), this vulnerability requires high attack complexity but can lead to partial confidentiality, integrity, and availability compromise. While not listed in CISA's KEV catalog, exploit modules are available in Metasploit and ExploitDB, and it has garnered some community discussion, indicating awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.49CPE matchmatch criteria
cpe:2.3:a:chkrootkit:chkrootkit:*:*:*:*:*:*:*:*
10.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:lts:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:lts:*:*:*:*:*
13.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 2.0

3.7LOW

AV:L/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
1.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.83%
Probability of exploitation in next 30 days
EPSS Percentile
89.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: Chkrootkit Local Privilege Escalation · Jun 4, 2014
ExploitDB: EDB-38775 · Nov 20, 2015
This CVE's current EPSS score of 0.0383 is in the 100th percentile among its peer group of 747 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

osvdb.org / show/osvdb/107710
packetstormsecurity.com / files/134484/Chkrootkit-Local-Privilege-Escalation.html
security.gentoo.org / glsa/201709-05
exploit-db.com / exploits/38775
chkrootkit.org
Vendor Advisory
debian.org / security/2014/dsa-2945
openwall.com / lists/oss-security/2014/06/04/9
Exploit
ubuntu.com / usn/USN-2230-1