libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1.0.5-1", "binary_name": "libqb-dev" }, { "binary_version": "1.0.5-1", "binary_name": "libqb-dev-dbgsym" }, { "binary_version": "1.0.5-1", "binary_name": "libqb-doc" }, { "binary_version": "1.0.5-1", "binary_name": "libqb0" }, { "binary_version": "1.0.5-1", "binary_name": "libqb0-dbgsym" } ] }