CVE-2016-6253 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 3.6% (pctl 89)
Patch early
A public exploit exists.
Description
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.56% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-59 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-01-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| netbsd | netbsd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit) | 2016-09-15 |
| exploit-db | NetBSD - 'mail.local(8)' Local Privilege Escalation | 2016-07-21 |
References
- http://akat1.pl/?id=2
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2016-006.txt.asc
- http://packetstormsecurity.com/files/138021/NetBSD-mail.local-8-Local-Root.html
- http://www.rapid7.com/db/modules/exploit/unix/local/netbsd_mail_local
- http://www.securityfocus.com/bid/92101
- http://www.securitytracker.com/id/1036429
- https://www.exploit-db.com/exploits/40141/
- https://www.exploit-db.com/exploits/40385/
- http://akat1.pl/?id=2
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2016-006.txt.asc
- http://packetstormsecurity.com/files/138021/NetBSD-mail.local-8-Local-Root.html
- http://www.rapid7.com/db/modules/exploit/unix/local/netbsd_mail_local
- http://www.securityfocus.com/bid/92101
- http://www.securitytracker.com/id/1036429
- https://www.exploit-db.com/exploits/40141/
- https://www.exploit-db.com/exploits/40385/
→ the Explorer · watch your stack · NVD