Overview
Pine is a mail user agent (MUA) written and distributed by the University of Washington. Some versions contain a buffer overflow vulnerability in email address handling.
Description
Impact
An attacker can construct a message with a crafted From: header that will cause Pine to crash with a segmentation fault, possibly resulting in a core dump. Pine users may be unable to restart the application if messages containing the crafted From: headers appear in mailboxes that Pine is configured to check at startup. Additionally, it may be possible for intruders to execute code on the heap of systems using vulnerable versions of the software. The code would be executed in the context of the user running the Pine program. |
Solution
Pine 4.50 has been released and contains a patch for this vulnerability. Users of versions earlier than 4.50 are encouraged to upgrade. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Linus Sjrg for reporting this vulnerability.
This document was written by Chad R Dougherty.
Other Information
CVE IDs: | CVE-2002-1320 |
Severity Metric: | 10.94 |
Date Public: | 2002-11-07 |
Date First Published: | 2002-12-09 |
Date Last Updated: | 2003-01-09 15:51 UTC |
Document Revision: | 14 |