CVE-2006-5327
Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAR_OPTIONS environment variable settings, when gnutar is invoked by OpenBase.
- Affected products
- Openbase Sql, Gnu Tar, Gzip
- Apple Xcode
- ≤ 2.2
- Openbase International Ltd Openbase
- ≤ 10.0, 7.0.15, 8.0.4, 9.1.5
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 0.6% (45th percentile)
- NVD status
- Modified
- Published
- 2006-10-17
CVE-2006-5327 at NVD
No indexed exploits for CVE-2006-5327 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2006-5327 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.