SLocate User-Supplied Database Heap Overflow Vulnerability
BID:8780
Info
SLocate User-Supplied Database Heap Overflow Vulnerability
| Bugtraq ID: | 8780 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0848 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery credited to Patrik Hornik. |
| Vulnerable: |
Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Workstation 6.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Server 6.5 Turbolinux Turbolinux Server 6.1 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux Advanced Server 6.0 Sun Cobalt RaQ XTR Sun Cobalt RaQ 4 Sun Cobalt Qube 3 slocate slocate 2.6 slocate slocate 2.5 slocate slocate 2.4 slocate slocate 2.3 slocate slocate 2.2 slocate slocate 2.1 SGI ProPack 2.4 SGI ProPack 2.3 |
| Not Vulnerable: |
slocate slocate 2.7 |
Discussion
SLocate User-Supplied Database Heap Overflow Vulnerability
It has been reported that a local off-by-one heap overflow exists in the handling of user-supplied databases by slocate. Because of this, an attacker may be able to gain elevated privileges.
It has been reported that a local off-by-one heap overflow exists in the handling of user-supplied databases by slocate. Because of this, an attacker may be able to gain elevated privileges.
Exploit / POC
SLocate User-Supplied Database Heap Overflow Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
References
SLocate User-Supplied Database Heap Overflow Vulnerability
References:
References:
- Product Homepage (slocate)
- RaQ XTR Patch Page (Sun)
- RHSA-2004-041 - Updated slocate packages fix vulnerabilities (RedHat)
- SA-20031006 slocate buffer overflow - exploitation proof (Patrik Hornik
) - SA-20031006 slocate vulnerability (Patrik Hornik
)