Description
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/output file, a different vulnerability than CVE-2006-5328.
Affected products
- openbase_international_ltd / openbase7.0.15 – 7.0.15
- openbase_international_ltd / openbase8.0.4 – 8.0.4
- openbase_international_ltd / openbase9.1.5 – 9.1.5
- openbase_international_ltd / openbase10.0 – 10.0