|
|
Subscribe / Log in / New account

slocate: buffer overflow

Package(s):slocate CVE #(s):CAN-2003-0848
Created:January 20, 2004 Updated:February 16, 2004
Description: A vulnerability was discovered in slocate, a program to index and search for files, whereby a specially crafted database could overflow a heap-based buffer. This vulnerability could be exploited by a local attacker to gain the privileges of the "slocate" group, which can access the global database containing a list of pathnames of all files on the system, including those which should only be visible to privileged users. This problem, and a category of potential similar problems, can be fixed by modifying slocate to drop privileges before reading a user-supplied database.
Alerts:
Fedora-Legacy FLSA:1232 slocate 2004-02-11
Whitebox WBSA-2004:041-01 slocate 2004-02-12
SCO Group CSSA-2004-001.0 slocate 2004-02-10
Fedora FEDORA-2004-059 slocate 2004-01-26
Red Hat RHSA-2004:041-01 slocate 2004-01-22
Mandrake MDKSA-2004:004 slocate 2004-01-23
Trustix 2004-0005 slocate 2004-01-21
Debian DSA-428-1 slocate 2004-01-20

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds