USN-373-1: mutt vulnerabilities

Ubuntu Security Notice USN-373-1

1st November, 2006

mutt vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 6.10
  • Ubuntu 6.06 LTS
  • Ubuntu 5.10

Details

Race conditions were discovered in mutt's handling of temporary files.
Under certain conditions when using a shared temp directory (the
default), other local users could overwrite arbitrary files owned by the
user running mutt. This vulnerability is more likely when the temp
directory is over NFS.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 6.10:
mutt 1.5.12-1ubuntu1.1
Ubuntu 6.06 LTS:
mutt 1.5.11-3ubuntu2.2
Ubuntu 5.10:
mutt 1.5.9-2ubuntu1.2

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system upgrade you need to restart mutt to effect the
necessary changes.

References

CVE-2006-5297, CVE-2006-5298