Back

LOW

Multiple mutt tempfile race conditions

Published Oct 16, 2006

Description

Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1 which is in maintenance mode.

Weaknesses (0)

No CWE recorded.

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 16, 2006
Updated Aug 7, 2024
Reserved Oct 16, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 4, 2006