CVE-2016-6253

EUVD-2016-7183
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
netbsdnetbsd
6.0
netbsdnetbsd
6.0.1
netbsdnetbsd
6.0.2
netbsdnetbsd
6.0.3
netbsdnetbsd
6.0.4
netbsdnetbsd
6.0.5
netbsdnetbsd
6.0.6
netbsdnetbsd
6.1
netbsdnetbsd
6.1.1
netbsdnetbsd
6.1.2
netbsdnetbsd
6.1.3
netbsdnetbsd
6.1.4
netbsdnetbsd
6.1.5
netbsdnetbsd
7.0
𝑥
= Vulnerable software versions