20001126 [MSY] S(ecure)Locate heap corruption vulnerabilitymailing list
http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html CVE-2001-0066
dislocate 1.3 - Local i386
Record summary
CVE-2001-0066 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBdislocate 1.3 - Local i386ExploitDB exploitby Michel KaempfNot analyzed1 file
References
9CLA-2001:369Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000369 DSA-005-1Vendor advisory
http://www.debian.org/security/2000/20001217a MDKSA-2000:085Vendor advisory
http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3 RHSA-2000:128Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-128.html 2004vdb entry
http://www.securityfocus.com/bid/2004 TLSA2001002-1Vendor advisory
http://www.turbolinux.com/pipermail/tl-security-announce/2001-February/000144.html slocate-heap-execute-code(5594)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5594 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0066