CVE-2023-32190
published 2024-10-16CVE-2023-32190: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mlocate | — | — |
| suse | opensuse_tumbleweed | >= ? < 0.26-37.1 | 0.26-37.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.5HIGH
vendor_debian8.5LOW
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mlocate: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable
vendor_redhat·2024-10-16·CVSS 8.5
CVE-2023-32190 [HIGH] CWE-732 mlocate: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable
mlocate: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
A flaw was found in the mlocate package of OpenSUSE and derived distributions. This issue occurs due to a insecure chmod call in the %post section of the mlocate package, allowing users to obtain read/write access to arbitrary files on the system when the mlocate package is re-installed or upgraded.
Statement: This flaw is specific to OpenSUSE and derived distributions. Therefore, Red Hat products are not affected by this issue.
Package: mlocate (Red Hat Enterprise Linux 7) - Not affected
Package: mlocate (Red Hat Enterprise Linux 8)
Debian
CVE-2023-32190: mlocate - mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world...
vendor_debian·2023·CVSS 8.5
CVE-2023-32190 [HIGH] CVE-2023-32190: mlocate - mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world...
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
Scope: local
bullseye: resolved
GHSA
GHSA-f97f-26jc-gffx: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privi
ghsa_unreviewed·2024-10-16
CVE-2023-32190 [HIGH] CWE-125 GHSA-f97f-26jc-gffx: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privi
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
OSV
CVE-2023-32190: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privi
osv·2024-10-16·CVSS 8.5
CVE-2023-32190 [HIGH] CVE-2023-32190: mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privi
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-16
Published