CVE-2006-1587: Low severity netbsd netbsd vulnerability
Published Apr 3, 2006
·Updated
NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.
Affected Software
10 affected components
NetBSD NetBSD=1.6
NetBSD NetBSD=1.6-beta
NetBSD NetBSD=1.6.1
NetBSD NetBSD=1.6.2
NetBSD NetBSD=2.0
NetBSD NetBSD=2.0.1
NetBSD NetBSD=2.0.2
NetBSD NetBSD=2.0.3
NetBSD NetBSD=2.1
NetBSD NetBSD=3.0
Event History
Apr 3, 2006
CVE Published
10:04 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1587?
CVE-2006-1587 has been classified with a medium severity level due to its potential for local user exploitation.
2
How do I fix CVE-2006-1587?
To fix CVE-2006-1587, change the file permissions for the record file to restrict access to unauthorized users.
3
Who is affected by CVE-2006-1587?
CVE-2006-1587 affects users of NetBSD versions from 1.6 up to 3.0.
4
What is the nature of the vulnerability in CVE-2006-1587?
CVE-2006-1587 is a local file permission vulnerability that allows local users to read sensitive record files.
5
What are the potential consequences of CVE-2006-1587?
The potential consequences of CVE-2006-1587 include unauthorized access to users' email records by other local users.