Vulnerability Details CVE-2001-1036
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.8%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2001-1036
-
cpe:2.3:a:gnu:findutils:4.0
-
cpe:2.3:a:gnu:findutils:4.1
-
cpe:2.3:o:slackware:slackware_linux:7.1
-
cpe:2.3:o:slackware:slackware_linux:8.0