Vulnerability Name: | CVE-2003-0848 (CCN-13354) | ||||||||||||||||||||
Assigned: | 2003-10-06 | ||||||||||||||||||||
Published: | 2003-10-06 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used. | ||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
References: | Source: SCO Type: UNKNOWN CSSA-2004-001.0 Source: SGI Type: UNKNOWN 20040201-01-U Source: SGI Type: UNKNOWN 20040202-01-U Source: CCN Type: BugTraq Mailing List, Mon Oct 06 2003 - 13:10:47 CDT SA-20031006 slocate vulnerability Source: MITRE Type: CNA CVE-2003-0848 Source: CCN Type: Fedora Security Update Notification FEDORA-2004-059 slocate Source: BUGTRAQ Type: UNKNOWN 20031006 SA-20031006 slocate vulnerability Source: BUGTRAQ Type: UNKNOWN 20031011 SA-20031006 slocate buffer overflow - exploitation proof Source: CCN Type: RHSA-2004-040 Updated slocate packages fix vulnerability Source: REDHAT Type: UNKNOWN RHSA-2004:040 Source: CCN Type: RHSA-2004-041 slocate security update Source: SECUNIA Type: UNKNOWN 10670 Source: SECUNIA Type: UNKNOWN 10683 Source: SECUNIA Type: UNKNOWN 10686 Source: SECUNIA Type: UNKNOWN 10698 Source: SECUNIA Type: UNKNOWN 10702 Source: SECUNIA Type: UNKNOWN 10720 Source: SECUNIA Type: UNKNOWN 10722 Source: CCN Type: SA9962 slocate User Database Privilege Escalation Vulnerability Source: SECUNIA Type: UNKNOWN 9962 Source: DEBIAN Type: Patch, Vendor Advisory DSA-428 Source: DEBIAN Type: DSA 428-1 slocate Source: DEBIAN Type: DSA-428 slocate -- buffer overflow Source: MISC Type: UNKNOWN http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt Source: MISC Type: UNKNOWN http://www.ebitech.sk/patrik/SA/SA-20031006.txt Source: CCN Type: slocate Web site Secure Locate Source: CCN Type: Trustix Secure Linux Security Advisory #2004-0005 slocate Source: MANDRAKE Type: UNKNOWN MDKSA-2004:004 Source: FEDORA Type: UNKNOWN FEDORA-2004-059 Source: REDHAT Type: UNKNOWN RHSA-2004:041 Source: CCN Type: SecuriTeam Mailing List, UNIX focus 13 Oct 2003 slocate Buffer Overflow (-i, -d, Exploit) Source: CCN Type: SCO Security Advisory CSSA-2004-001.0 OpenLinux: slocate local user buffer overflow Source: CCN Type: BID-8780 SLocate User-Supplied Database Heap Overflow Vulnerability Source: CCN Type: BID-8790 LTrace Local Command Line Parameter Heap Overflow Vulnerability Source: TRUSTIX Type: UNKNOWN 2004-0005 Source: CCN Type: TLSA-2004-6 Buffer overlows Source: XF Type: UNKNOWN slocate-heap-bo(13354) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11033 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:821 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |