LOW · 2.1

CVE-2006-3159

pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified b...

Vulnerability Description

pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SunIplanet Messaging Server5.2
SunOne Messaging Server5.2

References

FAQ

What is CVE-2006-3159?

CVE-2006-3159 is a vulnerability with a CVSS score of 2.1 (LOW). pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified b...

How severe is CVE-2006-3159?

CVE-2006-3159 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-3159?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Iplanet Messaging Server, Sun One Messaging Server.