mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
Metrics
Affected Vendors & Products
References
History
Sat, 19 Oct 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-732 |
Thu, 17 Oct 2024 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 16 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Suse
Suse opensuse Tumbleweed |
|
CPEs | cpe:2.3:a:suse:opensuse_tumbleweed:*:*:*:*:*:*:*:* | |
Vendors & Products |
Suse
Suse opensuse Tumbleweed |
|
Metrics |
cvssV3_1
|
Wed, 16 Oct 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges. | |
Title | mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: suse
Published: 2024-10-16T12:03:05.078Z
Updated: 2024-10-16T16:08:11.305Z
Reserved: 2023-05-04T08:30:59.321Z
Link: CVE-2023-32190
Vulnrichment
Updated: 2024-10-16T16:08:01.523Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T12:15:07.460
Modified: 2024-10-16T16:38:14.557
Link: CVE-2023-32190
Redhat