Description of problem: Setgid programs should have full RELRO support enabled for extra protection. It should also have gcc's PIE flag enabled, too. FILE TYPE RELRO PIE /usr/bin/locate setgid partial no You can use this test program for testing: http://people.redhat.com/sgrubb/files/rpm-chksec
Fixed in mlocate-0.26-1. Thanks for your report.
mlocate-0.26-1.fc18 has been submitted as an update for Fedora 18. https://admin.fedoraproject.org/updates/mlocate-0.26-1.fc18
Package mlocate-0.26-1.fc18: * should fix your issue, * was pushed to the Fedora 18 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing mlocate-0.26-1.fc18' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2012-14583/mlocate-0.26-1.fc18 then log in and leave karma (feedback).
mlocate-0.26-1.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.