Networking Forums

Networking Forums > Computer Networking > Linux Networking > Vulnerability in UW Pine <= 4.56

Reply
Thread Tools Display Modes

Vulnerability in UW Pine <= 4.56

 
 
Jem Berkes
Guest
Posts: n/a

 
      09-11-2003, 12:40 PM
Pine 4.58 was released 2003-09-10 to fix this vulnerability. See:
http://www.idefense.com/advisory/09.10.03.txt
http://www.washington.edu/pine/changes.html

"
PINE contains two exploitable vulnerabilities that can be triggered
when a victim opens a specially crafted email sent by an attacker.
....
Vulnerability 1: Buffer Overflow
....
Vulnerability 2: Integer Overflow
....

III. ANALYSIS

If an attacker were to socially engineer a PINE user into opening a
malformed e-mail message, arbitrary code embedded within can then run
with privileges of the currently logged on user. It would be trivial
for this exploit to be fashioned into a worm, targeting e-mail
addresses found in any readable text files (inbox, etc.).

IV. DETECTION

PINE 4.56 and earlier is vulnerable.
....

VII. DISCLOSURE TIMELINE

15 AUG 2003 Issues acquired by iDEFENSE
25 AUG 2003 Issues disclosed to (E-Mail Removed)
25 AUG 2003 Response from Mark Crispin, University of Washington
26 AUG 2003 Issues disclosed to iDEFENSE clients
04 SEP 2003 Issues disclosed to Linux vendors: vendor-(E-Mail Removed)
10 SEP 2003 Coordinated Public Disclosure

VIII. CREDIT

zen-parse (zen-(E-Mail Removed)) discovered these vulnerabilities.
"
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ipv6 vulnerability explained BigRedTruck Linux Networking 6 07-27-2011 05:11 PM
DD-WRT Vulnerability Announced. 1PW Network Routers 0 07-25-2009 01:54 AM
trying to use pine with postfix Sven-Thorsten Fahrbach Linux Networking 2 06-19-2005 12:03 AM
security vulnerability? Sally P. Wireless Internet 2 09-19-2004 02:10 AM
port 22222 vulnerability Allan Bruce Linux Networking 9 10-25-2003 10:23 AM



1 2 3 4 5 6 7 8 9 10 11