CVE-2006-5298

NameCVE-2006-5298
DescriptionThe mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier does not properly verify that temporary files have been created with restricted permissions, which might allow local users to create files with weak permissions via a race condition between the mktemp and safe_fopen function calls.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow
Debian Bugs396104

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mutt (PTS)stretch1.7.2-1+deb9u3fixed
stretch (security)1.7.2-1+deb9u5fixed
buster, buster (security)1.10.1-2.1+deb10u5fixed
bookworm, sid, bullseye2.0.5-4.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
muttsource(unstable)1.5.13-1.1low396104

Notes

[sarge] - mutt <no-dsa> (Minor issue, tmp dirs on NFS cause problems in many scenarios)

Search for package or bug name: Reporting problems