Secure Locate Local Information Disclosure Vulnerability
BID:21989
Info
Secure Locate Local Information Disclosure Vulnerability
| Bugtraq ID: | 21989 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-0227 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 10 2007 12:00AM |
| Updated: | Apr 17 2014 12:40AM |
| Credit: | [email protected] discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 slocate slocate 3.0 beta r3 slocate slocate 3.1 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux -current Foresight Linux Foresight Linux 1.1 |
| Not Vulnerable: | |
Discussion
Secure Locate Local Information Disclosure Vulnerability
Secure Locate is prone to a local information-disclosure vulnerability because the utility fails to properly interpret filesystem permissions.
Successfully exploiting this issue allows attackers to gain access to the names of files located in directories they do not have permissions to access. Information that attackers harvest may aid them in further attacks.
Secure Locate 3.1 is vulnerable to this issue; other versions may also be affected.
Secure Locate is prone to a local information-disclosure vulnerability because the utility fails to properly interpret filesystem permissions.
Successfully exploiting this issue allows attackers to gain access to the names of files located in directories they do not have permissions to access. Information that attackers harvest may aid them in further attacks.
Secure Locate 3.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Secure Locate Local Information Disclosure Vulnerability
Attackers use the 'slocate' utility itself to exploit this issue.
Attackers use the 'slocate' utility itself to exploit this issue.
Solution / Fix
Secure Locate Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
slocate slocate 3.1
slocate slocate 3.0 beta r3
Solution:
Updates are available. Please see the references for more information.
slocate slocate 3.1
-
Ubuntu slocate_3.1-1ubuntu0.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_amd64.deb -
Ubuntu slocate_3.1-1ubuntu0.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_i386.deb -
Ubuntu slocate_3.1-1ubuntu0.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_i386.deb -
Ubuntu slocate_3.1-1ubuntu0.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_powerpc.deb -
Ubuntu slocate_3.1-1ubuntu0.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_powerpc.deb -
Ubuntu slocate_3.1-1ubuntu0.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_sparc.deb -
Ubuntu slocate_3.1-1ubuntu0.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.1-1ubu ntu0.1_sparc.deb
slocate slocate 3.0 beta r3
-
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_amd64.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_amd64.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_i386.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_i386.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_powerpc.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_powerpc.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_sparc.deb -
Ubuntu slocate_3.0.beta.r3-1ubuntu0.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/s/slocate/slocate_3.0.beta .r3-1ubuntu0.1_sparc.deb
References
Secure Locate Local Information Disclosure Vulnerability
References:
References: