Vulnerability Name:

CVE-2003-0848 (CCN-13354)

Assigned:2003-10-06
Published:2003-10-06
Updated:2017-10-11
Summary:Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: SCO
Type: UNKNOWN
CSSA-2004-001.0

Source: SGI
Type: UNKNOWN
20040201-01-U

Source: SGI
Type: UNKNOWN
20040202-01-U

Source: CCN
Type: BugTraq Mailing List, Mon Oct 06 2003 - 13:10:47 CDT
SA-20031006 slocate vulnerability

Source: MITRE
Type: CNA
CVE-2003-0848

Source: CCN
Type: Fedora Security Update Notification FEDORA-2004-059
slocate

Source: BUGTRAQ
Type: UNKNOWN
20031006 SA-20031006 slocate vulnerability

Source: BUGTRAQ
Type: UNKNOWN
20031011 SA-20031006 slocate buffer overflow - exploitation proof

Source: CCN
Type: RHSA-2004-040
Updated slocate packages fix vulnerability

Source: REDHAT
Type: UNKNOWN
RHSA-2004:040

Source: CCN
Type: RHSA-2004-041
slocate security update

Source: SECUNIA
Type: UNKNOWN
10670

Source: SECUNIA
Type: UNKNOWN
10683

Source: SECUNIA
Type: UNKNOWN
10686

Source: SECUNIA
Type: UNKNOWN
10698

Source: SECUNIA
Type: UNKNOWN
10702

Source: SECUNIA
Type: UNKNOWN
10720

Source: SECUNIA
Type: UNKNOWN
10722

Source: CCN
Type: SA9962
slocate User Database Privilege Escalation Vulnerability

Source: SECUNIA
Type: UNKNOWN
9962

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-428

Source: DEBIAN
Type: DSA 428-1
slocate

Source: DEBIAN
Type: DSA-428
slocate -- buffer overflow

Source: MISC
Type: UNKNOWN
http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt

Source: MISC
Type: UNKNOWN
http://www.ebitech.sk/patrik/SA/SA-20031006.txt

Source: CCN
Type: slocate Web site
Secure Locate

Source: CCN
Type: Trustix Secure Linux Security Advisory #2004-0005
slocate

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2004:004

Source: FEDORA
Type: UNKNOWN
FEDORA-2004-059

Source: REDHAT
Type: UNKNOWN
RHSA-2004:041

Source: CCN
Type: SecuriTeam Mailing List, UNIX focus 13 Oct 2003
slocate Buffer Overflow (-i, -d, Exploit)

Source: CCN
Type: SCO Security Advisory CSSA-2004-001.0
OpenLinux: slocate local user buffer overflow

Source: CCN
Type: BID-8780
SLocate User-Supplied Database Heap Overflow Vulnerability

Source: CCN
Type: BID-8790
LTrace Local Command Line Parameter Heap Overflow Vulnerability

Source: TRUSTIX
Type: UNKNOWN
2004-0005

Source: CCN
Type: TLSA-2004-6
Buffer overlows

Source: XF
Type: UNKNOWN
slocate-heap-bo(13354)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:11033

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:821

Vulnerable Configuration:Configuration 1:
  • cpe:/a:slocate:slocate:2.1:*:*:*:*:*:*:*
  • OR cpe:/a:slocate:slocate:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:slocate:slocate:2.3:*:*:*:*:*:*:*
  • OR cpe:/a:slocate:slocate:2.4:*:*:*:*:*:*:*
  • OR cpe:/a:slocate:slocate:2.5:*:*:*:*:*:*:*
  • OR cpe:/a:slocate:slocate:2.6:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:11033
    V
    Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.
    2013-04-29
    oval:org.mitre.oval:def:821
    V
    slocate Privilege Escalation Vulnerability
    2007-04-25
    oval:com.redhat.rhsa:def:20040041
    P
    RHSA-2004:041: slocate security update (Moderate)
    2004-01-22
    oval:org.debian:def:428
    V
    buffer overflow
    2004-01-20
    BACK
    slocate slocate 2.1
    slocate slocate 2.2
    slocate slocate 2.3
    slocate slocate 2.4
    slocate slocate 2.5
    slocate slocate 2.6