Vulnerability Name: | CVE-2001-1036 (CCN-6932) | ||||||||
Assigned: | 2001-08-01 | ||||||||
Published: | 2001-08-01 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Aug 01 2001 - 11:03:58 CDT Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate Source: CCN Type: BugTraq Mailing List, Wed Aug 01 2001 - 12:00:05 CDT Re: Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate Source: CCN Type: BugTraq Mailing List, Wed Aug 01 2001 - 15:21:37 CDT Re: Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate Source: CCN Type: BugTraq Mailing List, Wed Aug 01 2001 - 15:04:17 CDT Re: Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate Source: CCN Type: BugTraq Mailing List, Wed Aug 01 2001 - 15:55:39 CDT Re: Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate Source: MITRE Type: CNA CVE-2001-1036 Source: OSVDB Type: UNKNOWN 5477 Source: CCN Type: OSVDB ID: 36827 GNU findutils locate/locate.c visit_old_format Function Overflow Source: CCN Type: OSVDB ID: 5477 GNU findutils locate Memory Write Privilege Escalation Source: BUGTRAQ Type: UNKNOWN 20010801 Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate Source: BID Type: Exploit, Vendor Advisory 3127 Source: CCN Type: BID-3127 GNU Locate Arbitrary Command Execution Vulnerability Source: XF Type: UNKNOWN locate-command-execution(6932) Source: XF Type: UNKNOWN locate-command-execution(6932) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |