CVE-2023-32190

Publication date

2024-10-16 12:03:05

Family

suse

State

PUBLISHED

Description

mlocates %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.