CVE-2006-5297

Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems.

Score1.2
Access VectorLOCAL
Access ComplexityHIGH
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE
Published2006-10-16 03:07:00.000-04
Last Modified2017-10-10 09:31:19.000-04

Vulnerable Software List

VendorProductVersions
Mutt Mutt 0.95.6, 1.2.1, 1.2.5, 1.2.5.1, 1.2.5.12, 1.2.5.12 ol, 1.2.5.4, 1.2.5.5, 1.3.12, 1.3.12.1, 1.3.16, 1.3.17, 1.3.22

References

SourceLink
MLIST[mutt-dev] 20061004 security problem with temp files [was Re: mutt_adv_mktemp() ?]
MANDRIVAMDKSA-2006:190
REDHATRHSA-2007:0386
BID20733
TRUSTIX2006-0061
UBUNTUUSN-373-1
VUPENADV-2006-4176