slocate Local Buffer Overrun Vulnerability
BID:6676
Info
slocate Local Buffer Overrun Vulnerability
| Bugtraq ID: | 6676 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0056 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | The discovery of this vulnerability has been credited to the USG team. |
| Vulnerable: |
Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Workstation 6.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Server 6.5 Turbolinux Turbolinux Server 6.1 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux Advanced Server 6.0 slocate slocate 2.6 slocate slocate 2.5 SGI ProPack 2.4 SGI ProPack 2.3 |
| Not Vulnerable: |
slocate slocate 2.7 slocate slocate 2.1 |
Exploit / POC
slocate Local Buffer Overrun Vulnerability
It has been reported that a proof of concept exploit has been developed which exploits this vulnerability, and will be available to the public soon.
The following example has been given which demonstrates the overflow:
/usr/bin/slocate -c `perl -e "print 'A' x 1024"` -r `perl -e "print 'A' x 1024"`
It has been reported that a proof of concept exploit has been developed which exploits this vulnerability, and will be available to the public soon.
The following example has been given which demonstrates the overflow:
/usr/bin/slocate -c `perl -e "print 'A' x 1024"` -r `perl -e "print 'A' x 1024"`
References
slocate Local Buffer Overrun Vulnerability
References:
References:
- MDKSA-2003:015: slocate (Mandrake)
- re: slocate vulnerability (
) - slocate Product Page (Secure Locate)
- [USG- SA- 2003.001] USG Security Advisory (slocate) ([email protected])
- Re: [USG- SA- 2003.001] USG Security Advisory (slocate) (Kevin Lindsay
)