Security Advisory

CVE-2023-32190

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-10-16 12:03:05
Last updated 2025-03-19 14:39:07
Assigner suse
CVSS score 8.5
State PUBLISHED

Description

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.