GLSA: pine

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 12/02/02

  • Next message: jari.helenius@mawaron.com: "Potential Vuln in McAfee VirusScan 451"
    From: Daniel Ahlberg <aliz@gentoo.org>
    Date: Mon, 2 Dec 2002 14:39:20 +0100
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200212-1
    - - --------------------------------------------------------------------

    PACKAGE : pine
    SUMMARY : remote DOS
    DATE    : 2002-12-02 13:12 UTC
    EXPLOIT : remote

    - - --------------------------------------------------------------------

    An attacker can send a fully legal email message with a crafted
    From-header and thus forcing pine to core dump on startup.
    The only way to launch pine is manually removing the bad message
    either directly from the spool, or from another MUA. Until the
    message has been removed or edited there is no way of accessing
    the INBOX using pine.

    Read the full advisory at
    http://marc.theaimsgroup.com/?l=bugtraq&m=103668430620531&w=2 recommended that all Gentoo Linux users who are running

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-mail/pine-4.44-r5 and earlier update their systems as follows:

    emerge rsync
    emerge pine
    emerge clean

    - - --------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    raker@gentoo.org
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE962KFfT7nyhUpoZMRAuXRAJ98j+FOcW1T2+ltJNPhj2lPc7dU/gCfb8IK
    jEpRPKyGYvhU28yicSxYzCs=
    =E178
    -----END PGP SIGNATURE-----



    Relevant Pages

    • [Full-Disclosure] GLSA: pine
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200212-1 ... SUMMARY: remote DOS ... From-header and thus forcing pine to core dump on startup. ... emerge rsync ...
      (Full-Disclosure)
    • Re: SSL in NNTP?
      ... Alpine has always supported SSL and TLS in news, as do later versions of Pine. ... Science does not emerge from voting, party politics, or public debate. ...
      (comp.mail.pine)

  • Quantcast