pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iplanet_messaging_server | Sun | 5.2 (including) | 5.2 (including) |
One_messaging_server | Sun | 5.2 (including) | 5.2 (including) |