First published: Fri Sep 07 2001(Updated: )
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Merit Aaa Radius Server | =5.01 | |
Merit Aaa Radius Server | =3.8m |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1000 is considered a moderate severity vulnerability due to its potential for local users to read arbitrary files.
To fix CVE-2001-1000, ensure that the rlmadmin help file is not accessible via symlink and apply any available patches for the affected Merit AAA Server versions.
CVE-2001-1000 affects Merit AAA Server versions 3.8M and 5.01.
CVE-2001-1000 is exploited using a symlink attack that allows local users to read unauthorized files.
Local users on systems running vulnerable versions of the Merit AAA Server are impacted by CVE-2001-1000.