Vulnerability Name: | CVE-2003-0056 (CCN-11151) | ||||||||||||||||
Assigned: | 2003-01-24 | ||||||||||||||||
Published: | 2003-01-24 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument. | ||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: CCN Type: slocate FTP site slocate/ Source: CALDERA Type: UNKNOWN CSSA-2003-009.0 Source: CCN Type: SCO Security Advisory CSSA-2003-009.0 Linux: slocate command line buffer overflows Source: SGI Type: UNKNOWN 20040202-01-U Source: CCN Type: BugTraq Mailing List, Fri Jan 24 2003 - 23:42:39 CST Re: [USG- SA- 2003.001] USG Security Advisory (slocate) Source: MITRE Type: CNA CVE-2003-0056 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2003:643 slocate Source: BUGTRAQ Type: UNKNOWN 20030124 [USG- SA- 2003.001] USG Security Advisory (slocate) Source: BUGTRAQ Type: UNKNOWN 20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate) Source: BUGTRAQ Type: UNKNOWN 20030202 GLSA: slocate Source: CCN Type: USG Security Advisory USG- SA- 2003.001 24- Jan- 2003 slocate -- local buffer overflow Source: CCN Type: RHSA-2004-041 slocate security update Source: REDHAT Type: UNKNOWN RHSA-2004:041 Source: SECUNIA Type: UNKNOWN 10720 Source: CCN Type: SA7947 slocate buffer overflow Source: SECUNIA Type: UNKNOWN 7947 Source: CCN Type: SA7982 Gentoo updates to slocate Source: SECUNIA Type: UNKNOWN 7982 Source: CCN Type: SA8007 Mandrake updates to slocate Source: SECUNIA Type: UNKNOWN 8007 Source: SECUNIA Type: UNKNOWN 8118 Source: SECUNIA Type: UNKNOWN 8236 Source: SECUNIA Type: UNKNOWN 8749 Source: DEBIAN Type: Patch, Vendor Advisory DSA-252 Source: DEBIAN Type: DSA-252 slocate -- buffer overflow Source: CCN Type: slocate Web site Secure Locate v2.6 Source: CCN Type: Gentoo Linux Security Announcement 200302-02 slocate -- buffer overflow Source: MANDRAKE Type: UNKNOWN MDKSA-2003:015 Source: CONECTIVA Type: UNKNOWN CLA-2003:643 Source: CCN Type: BID-6676 slocate Local Buffer Overrun Vulnerability Source: CCN Type: TLSA-2004-6 Buffer overlows Source: MISC Type: Vendor Advisory http://www.usg.org.uk/advisories/2003.001.txt Source: XF Type: UNKNOWN slocate-command-line-bo(11151) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11369 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |