CVE-2019-12779: Clusterlabs Libqb
High severity, CVSS 7.1. EPSS: 0.7% chance of exploitation in the next 30 days.
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
Affected products
- Clusterlabs Libqb: before 1.0.5 (fixed in 1.0.5)
Published 2019-06-07. Last modified 2026-06-17.