Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Gentoo: 200212-1 Critical: Remote DoS from Pine Buffer Overflow

gentoo
Calendar Grey December 2, 2002
Dist Gentoo Esm H88
- -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNC
While parsing and escaping characters of eMail addresses pine does not allocate enough memory for storing the escaped mailbox part of an address.

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-1
- --------------------------------------------------------------------
DATE    : 2002-12-02 13:12 UTC

- --------------------------------------------------------------------
An attacker can send a fully legal email message with a crafted From-header and thus forcing pine to core dump on startup. The only way to launch pine is manually removing the bad message either directly from the spool, or from another MUA. Until the message has been removed or edited there is no way of accessing the INBOX using pine.
Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=103668430620531&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-mail/pine-4.44-r5 and earlier update their systems as follows:
emerge rsync emerge pine emerge clean
...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : pine
SUMMARY : remote DOS
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here