CVE-2003-0848: Slocate
Medium severity, CVSS 4.6. EPSS: 1% chance of exploitation in the next 30 days.
Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.
Affected products
- Slocate Slocate: version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only; version 2.6 only
Published 2003-11-17. Last modified 2026-06-16.