CVE-2001-0066 describes a memory corruption vulnerability in Secure Locate (slocate) that allows local users to execute arbitrary code. By crafting a malformed database file with an out-of-bounds offset, attackers can corrupt memory. This vulnerability is rated as High severity (CVSS 7.2) due to its local attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, public exploit code exists, and the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4CPE matchmatch criteria | cpe:2.3:a:kevin_lindsay:secure_locate:1.4:*:*:*:*:*:*:* | ||
1.5CPE matchmatch criteria | cpe:2.3:a:kevin_lindsay:secure_locate:1.5:*:*:*:*:*:*:* | ||
1.6CPE matchmatch criteria | cpe:2.3:a:kevin_lindsay:secure_locate:1.6:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:kevin_lindsay:secure_locate:2.0:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:kevin_lindsay:secure_locate:2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.