CVE-2016-6253: Netbsd

High severity, CVSS 7.8. EPSS: 3.5% chance of exploitation in the next 30 days.

mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.

Affected products

  • Netbsd Netbsd: version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.0.5 only; …

Published 2017-01-20. Last modified 2026-06-17.