First published: Thu Jun 22 2006(Updated: )
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun iPlanet Messaging Server | =5.2 | |
Sun iPlanet Messaging Server | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3159 is considered a moderate severity vulnerability due to its potential for exposing restricted file information to local users.
To fix CVE-2006-3159, ensure that improper symlinks are not used by restricting access permissions to sensitive files and reviewing the CONFIGROOT variable settings.
CVE-2006-3159 affects Sun ONE/iPlanet Messaging Server and Sun iPlanet Messaging Server version 5.2.
Exploitation of CVE-2006-3159 can allow local users to read portions of restricted files, potentially leading to information disclosure.
CVE-2006-3159 is not a remote vulnerability; it requires local access to the affected system to execute the symlink attack.