CVE-2001-1036

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:findutils:4.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:findutils:4.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:slackware:slackware_linux:7.1:*:*:*:*:*:*:*
cpe:2.3:o:slackware:slackware_linux:8.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:36

Type Values Removed Values Added
References () http://www.osvdb.org/5477 - () http://www.osvdb.org/5477 -
References () http://www.securityfocus.com/archive/1/200991 - () http://www.securityfocus.com/archive/1/200991 -
References () http://www.securityfocus.com/bid/3127 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/3127 - Exploit, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6932 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/6932 -

Information

Published : 2001-08-31 04:00

Updated : 2024-11-20 23:36


NVD link : CVE-2001-1036

Mitre link : CVE-2001-1036

CVE.ORG link : CVE-2001-1036


JSON object : View

Products Affected

slackware

  • slackware_linux

gnu

  • findutils