SB2016072209 - Race condition in mail.local in NetBSD
Published: July 22, 2016 Updated: September 14, 2018
Security Bulletin ID
SB2016072209
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition in mail.local (CVE-ID: CVE-2016-6253)
The vulnerability allows a local user to obtain root privileges on the target system.The vulnerability exists due to an access control error in NetBSD. A local user can exploit the race condition in mail.local(8) to change the ownership of arbitrary files or append arbitrary data to arbitrary files to gain root privileges on the target system.
Successful exploitation of this vulnerability may result in root access via local system.
Remediation
Install update from vendor's website.