First published: Mon Aug 26 1996(Updated: )
Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington PINE | <=3.94 | |
Slackware Linux | =3.0 | |
FreeBSD FreeBSD | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1187 is considered a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-1999-1187, upgrade Pine to version 3.94 or later to mitigate the symlink attack risk.
CVE-1999-1187 affects Pine versions prior to 3.94, Slackware Linux 3.0, and FreeBSD 2.1.0.
CVE-1999-1187 is associated with a local symlink attack that can lead to privilege escalation.
CVE-1999-1187 is a local vulnerability, which means it cannot be exploited remotely without local access.