Lucene search

K
redhatcveRedhat.comRH:CVE-2006-5298
HistoryOct 30, 2015 - 10:07 a.m.

CVE-2006-5298

2015-10-3010:07:17
redhat.com
access.redhat.com
6

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0

Percentile

5.1%

The mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier does not properly verify that temporary files have been created with restricted permissions, which might allow local users to create files with weak permissions via a race condition between the mktemp and safe_fopen function calls.

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0

Percentile

5.1%