pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-06-22 15:06
Updated : 2017-07-19 18:32
NVD link : CVE-2006-3159
Mitre link : CVE-2006-3159
JSON object : View
CWE
Products Affected
sun
- iplanet_messaging_server
- one_messaging_server