CVE
- Id
- 3805
- CVE No.
- CVE-2001-1000
- Status
- Candidate
- Description
- rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.
- Phase
- Proposed (20020131)
- Votes
- ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green
- Comments
- Frech> If the software is available to the general public, then it | should | be included in CVE. Marking the software "MichNet Only" does not | prevent | someone from running it outside of MichNet, but it allegedly may | protect | MichNet against actual or perceived liabilities.