xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8002.php | vdb entry patch vendor advisory |
ftp://patches.sgi.com/support/free/security/advisories/20020604-01-I | vendor advisory |
http://marc.info/?l=bugtraq&m=101223525118717&w=2 | mailing list |
http://www.securityfocus.com/bid/3969 | vdb entry |