OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xcode | Apple | * | 2.2 (including) |
Openbase | Openbase_international_ltd | * | 10.0 (including) |
Openbase | Openbase_international_ltd | 7.0.15 (including) | 7.0.15 (including) |
Openbase | Openbase_international_ltd | 8.0.4 (including) | 8.0.4 (including) |
Openbase | Openbase_international_ltd | 9.1.5 (including) | 9.1.5 (including) |