CVE-2006-5327: High severity Apple Xcode vulnerability
Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAROPTIONS environment variable settings, when gnutar is invoked by OpenBase.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5327?
CVE-2006-5327 is classified as a significant vulnerability allowing local users to execute arbitrary code.
How do I fix CVE-2006-5327?
To fix CVE-2006-5327, update to a version of OpenBase SQL that is newer than 10.0 or apply relevant patches provided by the vendor.
Who is affected by CVE-2006-5327?
CVE-2006-5327 affects local users running OpenBase SQL versions 10.0 and earlier, as well as Apple Xcode up to version 2.2.
What applications utilize the vulnerable components of CVE-2006-5327?
CVE-2006-5327 impacts applications that include OpenBase SQL and Apple Xcode, especially in configurations using specific versions.
Can CVE-2006-5327 be exploited remotely?
CVE-2006-5327 cannot be exploited remotely as it requires local user access and specific conditions to be met.