Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2005-2351

Опубликовано: 30 мая 2005
Источник: redhat
CVSS3: 5.5

Описание

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

An insecure temporary file vulnerability was found in the way mutt created temporary files under /tmp. Specifically, mutt created temporary files in an insecure way, using only predictable elements such as the hostname, user ID (uid) and process ID (pid). A local attacker could exploit this flaw to create those temporary files beforehand, causing a denial of service by preventing the user from using mutt.

Отчет

This flaw does not affect versions of mutt as shipped with Red Hat Enterprise Linux 7 and 8 as they already include the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5muttOut of support scope
Red Hat Enterprise Linux 6muttOut of support scope
Red Hat Enterprise Linux 7muttNot affected
Red Hat Enterprise Linux 8muttNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1768449mutt: denial of service via a series of requests to temporary files

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 6 лет назад

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

CVSS3: 5.5
nvd
почти 6 лет назад

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

CVSS3: 5.5
debian
почти 6 лет назад

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of ser ...

CVSS3: 5.5
github
больше 3 лет назад

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

5.5 Medium

CVSS3