CVE-2000-0353: Critical severity University of Washington pine vulnerability

Published Jun 28, 1999
·
Updated

Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.

Affected Software

4 affected components
University of Washington pine=4.0
University of Washington pine=4.2
University of Washington pine=4.10
University of Washington pine=3.98

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Pine 4.x from your environment.

    Uninstall or stop using Pine 4.x on affected systems until a vendor-supplied fix or patched version is available.

  2. Configuration

    Disable HTML rendering or automatic retrieval of external resources in Pine to prevent index.html from invoking lynx or fetching and executing remote uuencoded files.

    Pine HTML rendering / automatic external content retrieval = disabled
  3. Compensating control

    Block or restrict outbound HTTP/HTTPS access from hosts running Pine to untrusted web servers at the network perimeter (firewall/ACL) and restrict access to untrusted index.html files to prevent retrieval of malicious content.

Event History

Jun 28, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0353?

CVE-2000-0353 is classified as high severity due to its ability to allow remote command execution.

2

How do I fix CVE-2000-0353?

To fix CVE-2000-0353, upgrade to Pine version 4.21 or later, which addresses this vulnerability.

3

What versions of Pine are affected by CVE-2000-0353?

CVE-2000-0353 affects Pine versions 3.98, 4.0, 4.2, and 4.10.

4

How does CVE-2000-0353 allow exploitation?

CVE-2000-0353 allows exploitation by executing arbitrary commands via a crafted index.html file.

5

What type of attack is facilitated by CVE-2000-0353?

CVE-2000-0353 facilitates a remote code execution attack through compromised HTML content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203