CVE Vulnerabilities

CVE-2001-1036

Published: Aug 31, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

Affected Software

Name Vendor Start Version End Version
Findutils Gnu 4.0 (including) 4.0 (including)
Findutils Gnu 4.1 (including) 4.1 (including)

References