Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-5297


Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems.


Published

2006-10-16T19:07:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 1.2 (LOW)

CVSSv2 Vector

AV:L/AC:H/Au:N/C:N/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

1.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mutt mutt ≤ 1.5.12 Yes
Application mutt mutt 0.95.6 Yes
Application mutt mutt 1.2.1 Yes
Application mutt mutt 1.2.5 Yes
Application mutt mutt 1.2.5.1 Yes
Application mutt mutt 1.2.5.4 Yes
Application mutt mutt 1.2.5.5 Yes
Application mutt mutt 1.2.5.12 Yes
Application mutt mutt 1.2.5.12_ol Yes
Application mutt mutt 1.3.12 Yes
Application mutt mutt 1.3.12.1 Yes
Application mutt mutt 1.3.16 Yes
Application mutt mutt 1.3.17 Yes
Application mutt mutt 1.3.22 Yes
Application mutt mutt 1.3.24 Yes
Application mutt mutt 1.3.25 Yes
Application mutt mutt 1.3.27 Yes
Application mutt mutt 1.3.28 Yes
Application mutt mutt 1.4.0 Yes
Application mutt mutt 1.4.1 Yes
Application mutt mutt 1.4.2 Yes
Application mutt mutt 1.4.2.1 Yes
Application mutt mutt 1.5.3 Yes
Application mutt mutt 1.5.10 Yes

References