Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-5298
HistoryOct 16, 2006 - 12:00 a.m.

CVE-2006-5298

2006-10-1600:00:00
ubuntu.com
ubuntu.com
17

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

The mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier
does not properly verify that temporary files have been created with
restricted permissions, which might allow local users to create files with
weak permissions via a race condition between the mktemp and safe_fopen
function calls.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchmutt< 1.5.11-3ubuntu2.2UNKNOWN
ubuntu6.10noarchmutt< 1.5.12-1ubuntu1.1UNKNOWN
ubuntu7.04noarchmutt< 1.5.13-1.1ubuntu3UNKNOWN

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%