CVE-2006-5297: Race Condition
Race condition in the safeopen function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the OEXCL flag on NFS filesystems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5297?
CVE-2006-5297 is considered a medium severity vulnerability due to its potential for local users to overwrite arbitrary files.
How do I fix CVE-2006-5297?
To fix CVE-2006-5297, users should upgrade to a version of Mutt newer than 1.5.12, where this vulnerability has been addressed.
Who is affected by CVE-2006-5297?
CVE-2006-5297 affects users of Mutt mail client versions 1.5.12 and earlier, particularly when used on NFS filesystems.
What kind of vulnerability is CVE-2006-5297?
CVE-2006-5297 is a race condition vulnerability related to the creation of temporary files in the Mutt mail client.
Can CVE-2006-5297 be exploited remotely?
CVE-2006-5297 cannot be exploited remotely as it requires local access to the system where the vulnerable Mutt client is running.