First published: Mon Oct 16 2006(Updated: )
Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt Mutt | =1.3.12.1 | |
Mutt Mutt | =1.2.5.5 | |
Mutt Mutt | =0.95.6 | |
Mutt Mutt | =1.3.27 | |
Mutt Mutt | =1.4.2.1 | |
Mutt Mutt | =1.3.16 | |
Mutt Mutt | =1.2.5 | |
Mutt Mutt | =1.3.25 | |
Mutt Mutt | =1.4.1 | |
Mutt Mutt | <=1.5.12 | |
Mutt Mutt | =1.3.22 | |
Mutt Mutt | =1.2.5.12 | |
Mutt Mutt | =1.2.5.1 | |
Mutt Mutt | =1.2.5.4 | |
Mutt Mutt | =1.3.28 | |
Mutt Mutt | =1.3.24 | |
Mutt Mutt | =1.4.0 | |
Mutt Mutt | =1.2.1 | |
Mutt Mutt | =1.4.2 | |
Mutt Mutt | =1.3.17 | |
Mutt Mutt | =1.5.3 | |
Mutt Mutt | =1.2.5.12_ol | |
Mutt Mutt | =1.3.12 | |
Mutt Mutt | =1.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5297 is considered a medium severity vulnerability due to its potential for local users to overwrite arbitrary files.
To fix CVE-2006-5297, users should upgrade to a version of Mutt newer than 1.5.12, where this vulnerability has been addressed.
CVE-2006-5297 affects users of Mutt mail client versions 1.5.12 and earlier, particularly when used on NFS filesystems.
CVE-2006-5297 is a race condition vulnerability related to the creation of temporary files in the Mutt mail client.
CVE-2006-5297 cannot be exploited remotely as it requires local access to the system where the vulnerable Mutt client is running.