Vulnerability Name: | CVE-2006-5297 (CCN-29638) | ||||||||||||||||
Assigned: | 2006-10-04 | ||||||||||||||||
Published: | 2006-10-04 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems. | ||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N) 0.9 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2006-5297 Source: MLIST Type: UNKNOWN [mutt-dev] 20061004 security problem with temp files [was Re: mutt_adv_mktemp() ?] Source: CCN Type: BugTraq Mailing List, 2006-10-04 20:39:29 security problem with temp files [was Re: mutt_adv_mktemp() ?] Source: CCN Type: RHSA-2007-0386 Moderate: mutt security update Source: CCN Type: SA22613 Mutt Insecure Temporary File Creation Weaknesses Source: SECUNIA Type: UNKNOWN 22613 Source: SECUNIA Type: UNKNOWN 22640 Source: SECUNIA Type: UNKNOWN 22685 Source: SECUNIA Type: UNKNOWN 22686 Source: SECUNIA Type: UNKNOWN 25529 Source: CCN Type: ASA-2007-296 Mutt security update (RHSA-2007-0386) Source: MANDRIVA Type: UNKNOWN MDKSA-2006:190 Source: CCN Type: Mutt Web site The Mutt E-Mail Client Source: REDHAT Type: UNKNOWN RHSA-2007:0386 Source: BID Type: UNKNOWN 20733 Source: CCN Type: BID-20733 Mutt Insecure Temporary File Creation Multiple Vulnerabilities Source: TRUSTIX Type: UNKNOWN 2006-0061 Source: CCN Type: USN-373-1 mutt vulnerabilities Source: UBUNTU Type: UNKNOWN USN-373-1 Source: VUPEN Type: UNKNOWN ADV-2006-4176 Source: XF Type: UNKNOWN mutt-safeopen-race-condition(29638) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10601 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |