logblackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
A flaw was found in libqb. Isecure handling of temporari files could be exploited by a local attacker to overwrite privileged system files.
Upstream issue:
https://github.com/ClusterLabs/libqb/issues/338
References:
https://bugzilla.redhat.com/showbug.cgi?id=1685297