CVE-2023-32190 Information

Description

mlocate’s %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

Reference

https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32190

Share on: