CVE-2023-32190
Severity CVSS v4.0:
HIGH
Type:
CWE-125
Out-of-bounds Read
Publication date:
16/10/2024
Last modified:
15/04/2026
Description
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH



