Description
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.
Affected products
- openbase_international_ltd / openbase7.0.15 – 7.0.15
- openbase_international_ltd / openbase8.0.4 – 8.0.4
- openbase_international_ltd / openbase9.1.5 – 9.1.5
- openbase_international_ltd / openbase10.0 – 10.0