PT-2017-1212 · Netbsd · Netbsd
Akat1
·
Published
2017-01-20
·
Updated
2017-01-20
·
CVE-2016-6253
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetBSD versions 6.0 through 6.0.6
NetBSD versions 6.1 through 6.1.5
NetBSD versions 7.0
Description
The issue is related to an incorrect link resolution before file access in the mail.local service of the NetBSD operating system. This can be exploited by a local attacker to bypass protection and manipulate symbolic links, potentially allowing them to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
Recommendations
For NetBSD versions 6.0 through 6.0.6, consider restricting access to the mail.local service until a patch is available.
For NetBSD versions 6.1 through 6.1.5, avoid using the mail.local service for sensitive operations until the issue is resolved.
For NetBSD versions 7.0, as a temporary workaround, consider disabling the mail.local service to minimize the risk of exploitation.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netbsd