PT-2006-6020 · Mutt+1 · Mutt+1

Derek Martin

·

Publicado

2006-10-16

·

Atualizado

2016-10-18

·

CVE-2006-5298

CVSS v2.0

1.2

Baixa

VetorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mutt versions 1.5.12 and earlier
Description The issue arises from the mutt adv mktemp function in the Mutt mail client, which fails to properly verify that temporary files have been created with restricted permissions. This could allow local users to create files with weak permissions via a race condition between the mktemp and safe fopen function calls.
Recommendations For versions 1.5.12 and earlier, update to a version that addresses this issue, as the current version does not properly restrict permissions for temporary files.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2015-1458
CVE-2006-5298

Produtos afetados

Alt Linux
Mutt