CVE Vulnerabilities

CVE-2003-0848

Published: Nov 17, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative pathlen value to be used.

Affected Software

NameVendorStart VersionEnd Version
SlocateSlocate2.1 (including)2.1 (including)
SlocateSlocate2.2 (including)2.2 (including)
SlocateSlocate2.3 (including)2.3 (including)
SlocateSlocate2.4 (including)2.4 (including)
SlocateSlocate2.5 (including)2.5 (including)
SlocateSlocate2.6 (including)2.6 (including)
Red Hat Enterprise Linux 3RedHatslocate-0:2.7-3*
Red Hat Linux 9RedHat*
SlocateUbuntudapper*
SlocateUbuntudevel*
SlocateUbuntuedgy*
SlocateUbuntufeisty*

References