First published: Fri Nov 10 2006(Updated: )
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
David Branco Openbase | =7.0.15 | |
David Branco Openbase | =9.1.5 | |
David Branco Openbase | =8.0.4 | |
David Branco Openbase | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5852 is classified as a medium severity vulnerability due to the potential for local privilege escalation.
To mitigate CVE-2006-5852, ensure that your PATH environment variable does not include untrusted directories.
CVE-2006-5852 affects OpenBase versions 7.0.15, 8.0.4, 9.1.5, and 10.0.
Local users of OpenBase SQL on macOS systems are impacted by CVE-2006-5852.
CVE-2006-5852 is classified as an untrusted search path vulnerability.