CVE-2001-0066

secure_locate - Memory Corruption via Malformed Database File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0066. PoCs published by Michel Kaempf.

AI-analyzed exploit summary This exploit targets a local buffer overflow vulnerability in Secure Locate versions 1.3 to 2.3. It manipulates heap memory structures to achieve arbitrary code execution by overwriting function pointers with shellcode.

Description

Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michel Kaempf · clocallinux
https://www.exploit-db.com/exploits/216

This exploit targets a local buffer overflow vulnerability in Secure Locate versions 1.3 to 2.3. It manipulates heap memory structures to achieve arbitrary code execution by overwriting function pointers with shellcode.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Secure Locate v1.3 to v2.3
No auth needed
Prerequisites: Local access to the target system · Presence of vulnerable Secure Locate binary · Ability to execute the exploit binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Various Sources vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5594
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2004
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2000-128.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2000/20001217a
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000369

Scores

EPSS 0.0101
EPSS Percentile 58.7%

Details

Status published
Products (6)
kevin_lindsay/secure_locate 1.4
kevin_lindsay/secure_locate 1.5
kevin_lindsay/secure_locate 1.6
kevin_lindsay/secure_locate 2.0
kevin_lindsay/secure_locate 2.1
kevin_lindsay/secure_locate 2.2
Published Feb 16, 2001
Tracked Since Feb 18, 2026