CVE

CVE-2006-3159

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/06/2006
Last modified:
20/07/2017

Description

pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:iplanet_messaging_server:5.2:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_messaging_server:5.2:*:*:*:*:*:*:*