CVE-2006-5852: Medium severity Openbase International Ltd Openbase vulnerability
Published Nov 10, 2006
·Updated
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.
Affected Software
4 affected components
Openbase International Ltd Openbase=7.0.15
Openbase International Ltd Openbase=8.0.4
Openbase International Ltd Openbase=9.1.5
Openbase International Ltd Openbase=10.0
Event History
Nov 10, 2006
CVE Published
02:07 AM
Data Sourced
via NVD·02:07 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5852?
CVE-2006-5852 is classified as a medium severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2006-5852?
To mitigate CVE-2006-5852, ensure that your PATH environment variable does not include untrusted directories.
3
What versions of OpenBase are affected by CVE-2006-5852?
CVE-2006-5852 affects OpenBase versions 7.0.15, 8.0.4, 9.1.5, and 10.0.
4
Who is impacted by CVE-2006-5852?
Local users of OpenBase SQL on macOS systems are impacted by CVE-2006-5852.
5
What type of vulnerability is CVE-2006-5852?
CVE-2006-5852 is classified as an untrusted search path vulnerability.