CVE-2002-0014: High severity University of Washington pine vulnerability
Published Jul 26, 2002
·Updated
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
Affected Software
4 affected components
University of Washington pine=4.20
University of Washington pine=4.21
University of Washington pine=4.30
University of Washington pine=4.33
Remediation
Patch Available
Event History
Jul 26, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0014?
CVE-2002-0014 is classified as a high severity vulnerability due to its potential to allow remote command execution.
2
How do I fix CVE-2002-0014?
To fix CVE-2002-0014, upgrade to Pine version 4.44 or later, which addresses this vulnerability.
3
What types of software are affected by CVE-2002-0014?
CVE-2002-0014 affects Pine versions 4.20, 4.21, 4.30, and 4.33 from University of Washington.
4
How does CVE-2002-0014 enable an attack?
CVE-2002-0014 allows attackers to execute arbitrary commands by exploiting URL-handling through shell metacharacters.
5
Can I be compromised if I use a vulnerable version of Pine?
Yes, using a vulnerable version of Pine can lead to remote code execution, risking compromise of your system.