Family: Fedora Local Security Checks --> Category: infos
Fedora Core 1 2004-059: slocate Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the slocate package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2004-059 (slocate).
Slocate is a security-enhanced version of locate. Just like locate,
slocate searches through a central database (which is updated nightly)
for files which match a given pattern. Slocate allows you to quickly
find files anywhere on your system.
Patrik Hornik discovered a vulnerability in Slocate versions up to and
including 2.7 where a carefully crafted database could overflow a
heap-based buffer. A local user could exploit this vulnerability to gain
'slocate' group rights and then read the entire slocate database. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2003-0848 to this issue.
Users of Slocate should upgrade to these packages which contain a
patch from Kevin Lindsay which causes slocate to drop rights before
reading a user-supplied database.
Solution : http://www.fedoranews.org/updates/FEDORA-2004-059.shtml
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.