PoC Index

CVE-2001-1036

HIGH 7.2EPSS 0.9%

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.90% chance of exploitation in the next 30 days, 57th percentile
Published
2003-04-02
Updated
2024-08-08

ExploitDB entries (1)

References

Related