CVE-2001-1036
HIGH 7.2EPSS 0.9%
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.90% chance of exploitation in the next 30 days, 57th percentile
- Published
- 2003-04-02
- Updated
- 2024-08-08