← Back

CVE-2006-5298

nvd nist
Published: Oct 16, 2006Modified: Apr 23, 2026

JSON object

Loading...
1.2
Vector
AV:L/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 1.9 / Impact: 2.9
Source: NVD

Description

The mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier does not properly verify that temporary files have been created with restricted permissions, which might allow local users to create files with weak permissions via a race condition between the mktemp and safe_fopen function calls.

Affected (24)

Products: Mutt: Mutt
1 product
Mutt
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Mutt
Up to 1.5.12
Version 0.95.6
Version 1.2.1
Version 1.2.5.12
Version 1.2.5.12_ol
Version 1.2.5.1
Version 1.2.5.4
Version 1.2.5.5
Version 1.2.5
Version 1.3.12.1
Version 1.3.12
Version 1.3.16
Version 1.3.17
Version 1.3.22
Version 1.3.24
Version 1.3.25
Version 1.3.27
Version 1.3.28
Version 1.4.0
Version 1.4.1
Version 1.4.2.1
Version 1.4.2
Version 1.5.10
Version 1.5.3

References (16)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.