libqb provides high-performance, reusable features for client-server architecture, such as logging, tracing, inter-process communication (IPC), and polling.
Security Fix(es):
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.(CVE-2019-12779)
{ "severity": "High" }
{ "aarch64": [ "libqb-1.0.3-7.oe1.aarch64.rpm", "libqb-debuginfo-1.0.3-7.oe1.aarch64.rpm", "libqb-debugsource-1.0.3-7.oe1.aarch64.rpm", "libqb-devel-1.0.3-7.oe1.aarch64.rpm" ], "noarch": [ "libqb-help-1.0.3-7.oe1.noarch.rpm" ], "src": [ "libqb-1.0.3-7.oe1.src.rpm" ], "x86_64": [ "libqb-1.0.3-7.oe1.x86_64.rpm", "libqb-debuginfo-1.0.3-7.oe1.x86_64.rpm", "libqb-debugsource-1.0.3-7.oe1.x86_64.rpm", "libqb-devel-1.0.3-7.oe1.x86_64.rpm" ] }