CVE

Id
3805  
CVE No.
CVE-2001-1000  
Status
Candidate  
Description
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.  
Phase
Proposed (20020131)  
Votes
ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green  
Comments
Frech> If the software is available to the general public, then it | should | be included in CVE. Marking the software "MichNet Only" does not | prevent | someone from running it outside of MichNet, but it allegedly may | protect | MichNet against actual or perceived liabilities.