Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7480

Опубликовано: 21 июл. 2017
Источник: debian

Описание

rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rkhunterfixed1.4.4-1package
rkhunterfixed1.4.2-6+deb9u1stretchpackage
rkhunterfixed1.4.2-0.4+deb8u1jessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/06/29/2

  • http://rkhunter.cvs.sourceforge.net/viewvc/rkhunter/rkhunter/files/rkhunter?r1=1.549&r2=1.550&view=patch

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.

CVSS3: 9.8
nvd
больше 8 лет назад

rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.

CVSS3: 9.8
github
больше 3 лет назад

rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.