CVE-2001-0736

Pine <4.33 - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0736. PoCs published by mat.

AI-analyzed exploit summary This exploit leverages a race condition in Pico (and Pine) to overwrite arbitrary files by predicting the temporary file name. It creates a symlink to a controlled file, waits for the victim to edit a message, and then replaces the symlink with a writable file to capture the contents.

Description

Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mat · bashlocallinux
https://www.exploit-db.com/exploits/20493

This exploit leverages a race condition in Pico (and Pine) to overwrite arbitrary files by predicting the temporary file name. It creates a symlink to a controlled file, waits for the victim to edit a message, and then replaces the symlink with a writable file to capture the contents.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Racy
Target: University of Washington Pico (versions 3.8, 4.3) and Pine
Auth required
Prerequisites: Victim must be using Pine with specific editor settings · Attacker must predict the temporary file name · Attacker must have write access to /tmp
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=98749102621604&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=99106787825229&w=2
Patch, Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-047.php3?dis=8.0
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-042.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6367

Scores

EPSS 0.0081
EPSS Percentile 52.2%

Details

Status published
Products (12)
engardelinux/secure_linux 1.0.1
immunix/immunix 6.2
immunix/immunix 7.0
immunix/immunix 7.0_beta
mandrakesoft/mandrake_linux 7.1
mandrakesoft/mandrake_linux 7.2
mandrakesoft/mandrake_linux 8.0
mandrakesoft/mandrake_linux_corporate_server 1.0.1
redhat/linux 5.2
redhat/linux 6.2
... and 2 more
Published Oct 18, 2001
Tracked Since Feb 18, 2026