VulnerabilityModified
CVE-2007-0227
slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files.
MEDIUM 5.0EPSS 1.73%
Does this matter?
Lower severity and a low EPSS score (1.73%). Track it; it rarely justifies an emergency change on its own.
Description
slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files. NOTE: another researcher reports that the issue is not present in slocate 2.7.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- slocate/slocate
- Source
- cve@mitre.org
References
- http://osvdb.org/33465
- http://www.securityfocus.com/archive/1/456489/100/0/threaded
- http://www.securityfocus.com/archive/1/456530/100/0/threaded
- http://www.securityfocus.com/archive/1/456593/100/0/threaded
- http://www.securityfocus.com/archive/1/456739/100/0/threaded
- http://www.securityfocus.com/archive/1/464220/30/7320/threaded
- http://www.securityfocus.com/bid/21989
- http://www.ubuntu.com/usn/usn-425-1
- http://osvdb.org/33465
- http://www.securityfocus.com/archive/1/456489/100/0/threaded
- http://www.securityfocus.com/archive/1/456530/100/0/threaded
- http://www.securityfocus.com/archive/1/456593/100/0/threaded
- http://www.securityfocus.com/archive/1/456739/100/0/threaded
- http://www.securityfocus.com/archive/1/464220/30/7320/threaded
- http://www.securityfocus.com/bid/21989
- http://www.ubuntu.com/usn/usn-425-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.