V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2016-6253
CVE
HighConfirmedExploit available

mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arb…

CVSS
7.8
High
EPSS
0.07
p91
Published
2016-01-01
Updated
2016-01-01
Description

mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.

Tags · CWE
CWE-59
CAPEC-17
CAPEC-35
CAPEC-76
CAPEC-132
Affected products
Netbsd
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.073 · p91
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-59
└ via CAPEC-35 · CWE-59
└ via CAPEC-132 · CWE-59
└ via CAPEC-35 · CWE-59
Known exploits — Сканер-ВС
40141
exploitdb · https://www.exploit-db.com/exploits/40141
Enterprise
40385
exploitdb · https://www.exploit-db.com/exploits/40385
Enterprise
Affected software
ProductVendorStatus
netbsd*Tracked
Source databases
CVE
Related vulnerabilities