CVE-2017-7480

Severity CVSS v4.0:
Pending analysis
Type:
CWE-300 Channel Accessible by Non-Endpoint
Publication date:
21/07/2017
Last modified:
20/04/2025

Description

rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rootkit_hunter_project:rootkit_hunter:*:*:*:*:*:*:*:* 1.4.2 (including)