GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
| Software | From | Fixed in |
|---|---|---|
| gnu / findutils | 4.1 | 4.1.x |
| gnu / findutils | 4.0 | 4.0.x |
| slackware / slackware_linux | 8.0 | 8.0.x |
| slackware / slackware_linux | 7.1 | 7.1.x |