CVE-2006-5327
Summary
| CVE | CVE-2006-5327 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-17 21:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAR_OPTIONS environment variable settings, when gnutar is invoked by OpenBase. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Xcode | All | All | All | All |
| Application | Openbase International Ltd | Openbase | 7.0.15 | All | mac_os_x | All |
| Application | Openbase International Ltd | Openbase | 8.0.4 | All | mac_os_x | All |
| Application | Openbase International Ltd | Openbase | 9.1.5 | All | mac_os_x | All |
| Application | Openbase International Ltd | Openbase | All | All | mac_os_x | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| OpenBase SQL Privilege Escalation Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Apple Xcode Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apple Xcode WebObjects Plugin Privilege Escalation Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.digitalmunition.com | |
| Apple Xcode Bugs Let Local Users Gain System Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.digitalmunition.com | |
| Apple Xcode OpenBase Multiple Privilege Escalation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| APPLE-SA-2007-10-30 Xcode 2.5 Developer Tools | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| MISC:http://www.digitalmunition.com/DMA[2006-1016a].txt | MITRE | www.digitalmunition.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.