Race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems.
Link | Tags |
---|---|
http://secunia.com/advisories/25529 | third party advisory |
http://marc.info/?l=mutt-dev&m=115999486426292&w=2 | mailing list |
http://www.securityfocus.com/bid/20733 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10601 | vdb entry signature |
http://www.trustix.org/errata/2006/0061/ | vendor advisory |
http://secunia.com/advisories/22640 | third party advisory |
http://secunia.com/advisories/22613 | third party advisory |
http://secunia.com/advisories/22685 | third party advisory |
http://secunia.com/advisories/22686 | third party advisory |
http://www.ubuntu.com/usn/usn-373-1 | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2007-0386.html | vendor advisory |
http://www.vupen.com/english/advisories/2006/4176 | vdb entry |
http://www.mandriva.com/security/advisories?name=MDKSA-2006:190 | vendor advisory |