Lucene search

K
cveMitreCVE-2006-5298
HistoryOct 16, 2006 - 7:07 p.m.

CVE-2006-5298

2006-10-1619:07:00
mitre
web.nvd.nist.gov
39
mutt mail client
cve-2006-5298
file permissions
local users
race condition
security vulnerability

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%

The mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier does not properly verify that temporary files have been created with restricted permissions, which might allow local users to create files with weak permissions via a race condition between the mktemp and safe_fopen function calls.

Affected configurations

Nvd
Node
muttmuttRange1.5.12
OR
muttmuttMatch0.95.6
OR
muttmuttMatch1.2.1
OR
muttmuttMatch1.2.5
OR
muttmuttMatch1.2.5.1
OR
muttmuttMatch1.2.5.4
OR
muttmuttMatch1.2.5.5
OR
muttmuttMatch1.2.5.12
OR
muttmuttMatch1.2.5.12_ol
OR
muttmuttMatch1.3.12
OR
muttmuttMatch1.3.12.1
OR
muttmuttMatch1.3.16
OR
muttmuttMatch1.3.17
OR
muttmuttMatch1.3.22
OR
muttmuttMatch1.3.24
OR
muttmuttMatch1.3.25
OR
muttmuttMatch1.3.27
OR
muttmuttMatch1.3.28
OR
muttmuttMatch1.4.0
OR
muttmuttMatch1.4.1
OR
muttmuttMatch1.4.2
OR
muttmuttMatch1.4.2.1
OR
muttmuttMatch1.5.3
OR
muttmuttMatch1.5.10
VendorProductVersionCPE
muttmutt*cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:*
muttmutt0.95.6cpe:2.3:a:mutt:mutt:0.95.6:*:*:*:*:*:*:*
muttmutt1.2.1cpe:2.3:a:mutt:mutt:1.2.1:*:*:*:*:*:*:*
muttmutt1.2.5cpe:2.3:a:mutt:mutt:1.2.5:*:*:*:*:*:*:*
muttmutt1.2.5.1cpe:2.3:a:mutt:mutt:1.2.5.1:*:*:*:*:*:*:*
muttmutt1.2.5.4cpe:2.3:a:mutt:mutt:1.2.5.4:*:*:*:*:*:*:*
muttmutt1.2.5.5cpe:2.3:a:mutt:mutt:1.2.5.5:*:*:*:*:*:*:*
muttmutt1.2.5.12cpe:2.3:a:mutt:mutt:1.2.5.12:*:*:*:*:*:*:*
muttmutt1.2.5.12_olcpe:2.3:a:mutt:mutt:1.2.5.12_ol:*:*:*:*:*:*:*
muttmutt1.3.12cpe:2.3:a:mutt:mutt:1.3.12:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%