Exploitation Summary
EIP tracks 1 public exploit for CVE-2001-1000. PoCs published by Digital Shadow.
AI-analyzed exploit summary This exploit leverages a symbolic link vulnerability in the setuid root 'rlmadmin' utility of the Merit AAA RADIUS Server to read arbitrary files (e.g., /etc/shadow) by manipulating the 'rlmadmin.help' file. It creates a temporary directory, symlinks the target file, and invokes rlmadmin to disclose the file contents.
Description
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.
Exploits (1)
This exploit leverages a symbolic link vulnerability in the setuid root 'rlmadmin' utility of the Merit AAA RADIUS Server to read arbitrary files (e.g., /etc/shadow) by manipulating the 'rlmadmin.help' file. It creates a temporary directory, symlinks the target file, and invokes rlmadmin to disclose the file contents.