Multiple mutt tempfile race conditions
Published Oct 16, 2006
1.2
LOWCVSS 2.0
EPSS 0.36%
Description
Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems.
Affected products
No data.
- ≤ 1.5.12
- 0.95.6
- 1.2.1
- 1.2.5
- 1.2.5.1
- 1.2.5.4
- 1.2.5.5
- 1.2.5.12
- 1.2.5.12_ol
- 1.3.12
- 1.3.12.1
- 1.3.16
- 1.3.17
- 1.3.22
- 1.3.24
- 1.3.25
- 1.3.27
- 1.3.28
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.2.1
- 1.5.3
- 1.5.10
No data.
Red Hat Enterprise Linux 3
mutt-5:1.4.1-5.el3
Fixed · RHSA-2007:0386
Red Hat Enterprise Linux 4
mutt-5:1.4.1-12.0.3.el4
Fixed · RHSA-2007:0386
Red Hat Enterprise Linux 5
mutt-5:1.4.2.2-3.0.2.el5
Fixed · RHSA-2007:0386
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | mutt-5:1.4.1-5.el3 | Fixed | RHSA-2007:0386 |
| Red Hat Enterprise Linux 4 | mutt-5:1.4.1-12.0.3.el4 | Fixed | RHSA-2007:0386 |
| Red Hat Enterprise Linux 5 | mutt-5:1.4.2.2-3.0.2.el5 | Fixed | RHSA-2007:0386 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1 which is in maintenance mode.
No CWE recorded.
References (17)
- http://marc.info/?l=mutt-dev&m=115999486426292&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/22613 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22640 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22685 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22686 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25529 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:190 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2007-0386.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/20733 vdb-entryx_refsource_BID
- http://www.trustix.org/errata/2006/0061/ vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-373-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/4176 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-5297 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=211085 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2006-5297
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10601 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-5297
Change history (0)
No recorded changes yet.