libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_name": "libqb-dev", "binary_version": "1.0.5-1" }, { "binary_name": "libqb-dev-dbgsym", "binary_version": "1.0.5-1" }, { "binary_name": "libqb-doc", "binary_version": "1.0.5-1" }, { "binary_name": "libqb0", "binary_version": "1.0.5-1" }, { "binary_name": "libqb0-dbgsym", "binary_version": "1.0.5-1" } ] }