Lucene search

K
securityvulnsFULL-DISCLOSURESECURITYVULNS:VULN:6266
HistoryJun 15, 2006 - 12:00 a.m.

Sun iPlanet symbolic links problem

2006-06-1500:00:00
FULL-DISCLOSURE
vulners.com
28

pipe_master suid root application tries to read configuration from msg.conf file with relative path without checking for symbolic links. It makes it possible to read few trings from any file with symbolic link.

CPENameOperatorVersion
iplanet messaging servereq5.2