7.2
CVSSv2

CVE-2001-1036

Published: 31/08/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu findutils 4.0

gnu findutils 4.1

slackware slackware linux 7.1

slackware slackware linux 8.0

Exploits

source: wwwsecurityfocuscom/bid/3127/info GNU locate is an application that searches file databases for file names that match user-supplied patterns A boundary condition error can occur when the program reads database files composed in an "old" format, produced by GNU locate prior to version 40 and by Unix versions of locate and find ...