High severity7.8NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2023-32190
CVE-2023-32190
Description
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords5 versionspkg:deb/debian/mlocate?arch=sourcepkg:deb/ubuntu/mlocate?arch=src?distro=esm-infra/bionicpkg:deb/ubuntu/mlocate?arch=src?distro=esm-infra/xenialpkg:deb/ubuntu/mlocate?arch=src?distro=focalpkg:deb/ubuntu/mlocate?arch=src?distro=trusty/esm
>= 0+ 4 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.