Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59057
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-373-1 (mutt)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to mutt
announced via advisory USN-373-1.

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

Details follow:

Race conditions were discovered in mutt's handling of temporary files.
Under certain conditions when using a shared temp directory (the
default), other local users could overwrite arbitrary files owned by the
user running mutt. This vulnerability is more likely when the temp
directory is over NFS.

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 5.10:
mutt 1.5.9-2ubuntu1.2

Ubuntu 6.06 LTS:
mutt 1.5.11-3ubuntu2.2

Ubuntu 6.10:
mutt 1.5.12-1ubuntu1.1

After a standard system upgrade you need to restart mutt to effect the
necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-373-1

Risk factor : Low

CVSS Score:
1.2

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-5297
BugTraq ID: 20733
http://www.securityfocus.com/bid/20733
http://www.mandriva.com/security/advisories?name=MDKSA-2006:190
http://marc.info/?l=mutt-dev&m=115999486426292&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10601
http://www.redhat.com/support/errata/RHSA-2007-0386.html
http://secunia.com/advisories/22613
http://secunia.com/advisories/22640
http://secunia.com/advisories/22685
http://secunia.com/advisories/22686
http://secunia.com/advisories/25529
http://www.trustix.org/errata/2006/0061/
http://www.ubuntu.com/usn/usn-373-1
http://www.vupen.com/english/advisories/2006/4176
Common Vulnerability Exposure (CVE) ID: CVE-2006-5298
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.