CVE-2001-1036
Published Aug 31, 2001
Last updated 7 years ago
Overview
- Description
- GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gnu:findutils:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CA98BAA-CDE7-4255-B4A9-926CA2BF9783" }, { "criteria": "cpe:2.3:a:gnu:findutils:4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82F0B7F9-8A8E-4717-9C78-A26141AC66BC" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:slackware:slackware_linux:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0297F56-5F41-48FD-AB47-36E3BD2AB7E7" }, { "criteria": "cpe:2.3:o:slackware:slackware_linux:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78D76664-F4AC-470A-9686-3F708922A340" } ], "operator": "OR" } ] } ]