KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevateperfprivileges.sh chown calls.
{ "binaries": [ { "binary_name": "hotspot", "binary_version": "1.1.0+git20190211-1ubuntu2" } ] }
{ "binaries": [ { "binary_name": "hotspot", "binary_version": "1.3.0-2ubuntu1" } ] }
{ "binaries": [ { "binary_name": "hotspot", "binary_version": "1.3.0-2ubuntu4" } ] }