20001031 FW: Pine 4.30 now availablemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html CVE-2000-0909
UoW Pine 4.0.4/4.10/4.21 - 'From:' Remote Buffer Overflow
Record summary
CVE-2000-0909 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBUoW Pine 4.0.4/4.10/4.21 - 'From:' Remote Buffer OverflowExploitDB exploitby ArkaneNot analyzed1 file
References
7MDKSA-2000:073Vendor advisory
http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3 RHSA-2000:102Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-102.html 20000922 [ no subject ]mailing list
http://www.securityfocus.com/archive/1/84901 1709vdb entry
http://www.securityfocus.com/bid/1709 pine-check-mail-bo(5283)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5283 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0909