Vulnerability Description
OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Xcode | <= 2.2 |
| Openbase International Ltd | Openbase | <= 10.0 |
References
- http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html
- http://secunia.com/advisories/22390Vendor Advisory
- http://secunia.com/advisories/27441
- http://www.digitalmunition.com/DMA%5B2006-1016a%5D.txt
- http://www.digitalmunition.com/Xcode_OpenBase_createfile.pl
- http://www.securityfocus.com/bid/20562
- http://www.securitytracker.com/id?1018872
- http://www.vupen.com/english/advisories/2007/3665
- http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html
- http://secunia.com/advisories/22390Vendor Advisory
- http://secunia.com/advisories/27441
- http://www.digitalmunition.com/DMA%5B2006-1016a%5D.txt
- http://www.digitalmunition.com/Xcode_OpenBase_createfile.pl
- http://www.securityfocus.com/bid/20562
- http://www.securitytracker.com/id?1018872
FAQ
What is CVE-2006-5328?
CVE-2006-5328 is a vulnerability with a CVSS score of 7.2 (HIGH). OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file.
How severe is CVE-2006-5328?
CVE-2006-5328 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5328?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Xcode, Openbase International Ltd Openbase.