Vulnerability Description
rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rootkit Hunter Project | Rootkit Hunter | <= 1.4.2 |
Related Weaknesses (CWE)
References
- http://seclists.org/oss-sec/2017/q2/643Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201805-11Third Party Advisory
- http://seclists.org/oss-sec/2017/q2/643Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201805-11Third Party Advisory
FAQ
What is CVE-2017-7480?
CVE-2017-7480 is a vulnerability with a CVSS score of 9.8 (CRITICAL). rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.
How severe is CVE-2017-7480?
CVE-2017-7480 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7480?
Check the references section above for vendor advisories and patch information. Affected products include: Rootkit Hunter Project Rootkit Hunter.