Security Advisory
CVE-2023-32190
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.