CVE-1999-1187: Medium severity University of Washington pine vulnerability
Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pineto a version that resolves this vulnerability.Fixed in 3.94
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1187?
CVE-1999-1187 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-1999-1187?
To fix CVE-1999-1187, upgrade Pine to version 3.94 or later to mitigate the symlink attack risk.
What systems are affected by CVE-1999-1187?
CVE-1999-1187 affects Pine versions prior to 3.94, Slackware Linux 3.0, and FreeBSD 2.1.0.
What type of attack is associated with CVE-1999-1187?
CVE-1999-1187 is associated with a local symlink attack that can lead to privilege escalation.
Can CVE-1999-1187 be exploited remotely?
CVE-1999-1187 is a local vulnerability, which means it cannot be exploited remotely without local access.