xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
K-ashare | Xinet | 11.01 (including) | 11.01 (including) |
Irix | Sgi | 6.5 (including) | 6.5 (including) |
Irix | Sgi | 6.5.1 (including) | 6.5.1 (including) |
Irix | Sgi | 6.5.2 (including) | 6.5.2 (including) |
Irix | Sgi | 6.5.3 (including) | 6.5.3 (including) |
Irix | Sgi | 6.5.4 (including) | 6.5.4 (including) |
Irix | Sgi | 6.5.5 (including) | 6.5.5 (including) |
Irix | Sgi | 6.5.6 (including) | 6.5.6 (including) |
Irix | Sgi | 6.5.7 (including) | 6.5.7 (including) |
Irix | Sgi | 6.5.8 (including) | 6.5.8 (including) |
Irix | Sgi | 6.5.9 (including) | 6.5.9 (including) |
Irix | Sgi | 6.5.10 (including) | 6.5.10 (including) |
Irix | Sgi | 6.5.11 (including) | 6.5.11 (including) |
Irix | Sgi | 6.5.12 (including) | 6.5.12 (including) |
Irix | Sgi | 6.5.13 (including) | 6.5.13 (including) |
Irix | Sgi | 6.5.14 (including) | 6.5.14 (including) |
Irix | Sgi | 6.5.15 (including) | 6.5.15 (including) |