Submitted by KeesCook on Wed, 2006-11-01 12:06
Referenced CVEs:
CVE-2006-5297, CVE-2006-5298
Description:
===========================================================
Ubuntu Security Notice USN-373-1 November 01, 2006
mutt vulnerabilities
CVE-2006-5297, CVE-2006-5298
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
mutt 1.5.9-2ubuntu1.2
Ubuntu 6.06 LTS:
mutt 1.5.11-3ubuntu2.2
Ubuntu 6.10:
mutt 1.5.12-1ubuntu1.1
After a standard system upgrade you need to restart mutt to effect the
necessary changes.
Details follow:
Race conditions were discovered in mutt's handling of temporary files.
Under certain conditions when using a shared temp directory (the
default), other local users could overwrite arbitrary files owned by the
user running mutt. This vulnerability is more likely when the temp
directory is over NFS.


