Description: | Description:
The remote host is missing updates announced in advisory FLSA-2004:1232.
Slocate is a security-enhanced version of locate, designed to find files on a system via a central database.
A vulnerability has been found in Slocate versions up to and including 2.7 where a carefully crafted database could overflow a heap-based buffer. A local user could exploit this vulnerability to gain slocate group privileges and then read the entire slocate database. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0848 to this issue.
These packages also fix a buffer overflow that affected unpatched versions of Slocate prior to 2.7. This vulnerability could also allow a local user to gain slocate group privileges. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0056 to this issue.
Users of slocate should update to these update packages, which contain a backported security patch that corrects this issue.
Fedora Legacy would like to thank Patrik Hornik and Kevin Lindsay fir disclosing these issues, as well as Michael Schwendt for providing a backported fix for Red Hat Linux 7.2, 7.3, and 8.0.
Affected platforms: Redhat 7.2 Redhat 7.3 Redhat 8
Solution: http://www.securityspace.com/smysecure/catid.html?in=FLSA-2004:1232 http://rhn.redhat.com/errata/RHSA-2004-041.html
Risk factor : High
CVSS Score: 7.2
|