Title : OpenBase SQL "Library/OpenBase/bin/gnutar" Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-4058 CVE ID : CVE-2006-5327 - CVE-2006-5328
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-10-17
Technical Description
A vulnerability has been identified in OpenBase SQL, which could be exploited by local attackers to obtain elevated privileges. This flaw is due to errors in various binaries that invoke "/Library/OpenBase/bin/gnutar" in an insecure manner, which could be exploited by local attackers to run "gzip" without an absolute path and then execute arbitrary commands with "root" privileges by manipulating the "PATH" environment variable.