« List of all CVEs

CVE-2001-1036

Published: 4/2/2003 Last updated: 8/8/2024 Reserved: 1/31/2002

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-findutils

Products affected (1)

Product Vendor Version
n/a n/a 3.4.4

References (8)