Record summary

CVE-2001-1036 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGNU findutils 4.0/4.1 - Locate Arbitrary Command ExecutionExploitDB exploitby Josh SmithNot analyzed1 file
ExploitDB

PoC details

References

5