Package name slocate
Date December 18th, 2000
Advisory ID MDKSA-2000:085
Affected versions 6.0, 6.1, 7.0, 7.1, 7.2
Synopsis Updated slocate packages fix vulnerability in database reading code

Problem Description

Michael Kaempf reported a security problem in slocate (a secure version
of locate, a tool to quickly locate files on a filesystem) on bugtraq
which was originally discovered by zorgon. He discovered that there
was a bug in the database reading code which made it overwrite an
internal structure with some input. He then showed this could be
exploited to trick slocate into executing arbitrary code by pointing it
to a carefully crafted database.

Updated Packages

Mandrakelinux 6.0

 e7cf97e995637ccb44b6380f077158a4  6.0/RPMS/slocate-2.4-1.2mdk.i586.rpm
b5136dee9c73e46ce9b5b322ec267315  6.0/SRPMS/slocate-2.4-1.2mdk.src.rpm

Mandrakelinux 6.1

 f936734de53de01f560bfb21ade21d46  6.1/RPMS/slocate-2.4-1.2mdk.i586.rpm
b5136dee9c73e46ce9b5b322ec267315  6.1/SRPMS/slocate-2.4-1.2mdk.src.rpm

Mandrakelinux 7.0

 12cdf2c5967b33c47ea502fde3cb6eb7  7.0/RPMS/slocate-2.4-1.2mdk.i586.rpm
b5136dee9c73e46ce9b5b322ec267315  7.0/SRPMS/slocate-2.4-1.2mdk.src.rpm

Mandrakelinux 7.1

 86876e037c35ec71d60822fd83909a82  7.1/RPMS/slocate-2.4-1.2mdk.i586.rpm
b5136dee9c73e46ce9b5b322ec267315  7.1/SRPMS/slocate-2.4-1.2mdk.src.rpm

Mandrakelinux 7.2

 9aef7c832bab7ce7c54779df4093ea77  7.2/RPMS/slocate-2.4-1.1mdk.i586.rpm
a0ac029974980068cbe6ac3d6f4e71f9  7.2/SRPMS/slocate-2.4-1.1mdk.src.rpm


To upgrade automatically, use MandrivaUpdate.


Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.