5477vdb entry
http://www.osvdb.org/5477 CVE-2001-1036
GNU findutils 4.0/4.1 - Locate Arbitrary Command Execution
Record summary
CVE-2001-1036 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGNU findutils 4.0/4.1 - Locate Arbitrary Command ExecutionExploitDB exploitby Josh SmithNot analyzed1 file
References
520010801 Slackware 8.0, 7.1 Vulnerability: /usr/bin/locatemailing list
http://www.securityfocus.com/archive/1/200991 3127vdb entry
http://www.securityfocus.com/bid/3127 locate-command-execution(6932)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6932 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1036