CVE-2003-0848

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2003
Last modified:
03/04/2025

Description

Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:slocate:slocate:2.1:*:*:*:*:*:*:*
cpe:2.3:a:slocate:slocate:2.2:*:*:*:*:*:*:*
cpe:2.3:a:slocate:slocate:2.3:*:*:*:*:*:*:*
cpe:2.3:a:slocate:slocate:2.4:*:*:*:*:*:*:*
cpe:2.3:a:slocate:slocate:2.5:*:*:*:*:*:*:*
cpe:2.3:a:slocate:slocate:2.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools