VYPR

mlocate

by SUSE S.A.

CVEs (1)

  • CVE-2023-32190HigOct 16, 2024
    risk 0.51cvss 7.8epss 0.00

    mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.