First published: Fri Jul 26 2002(Updated: )
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington PINE | =4.20 | |
University of Washington PINE | =4.21 | |
University of Washington PINE | =4.30 | |
University of Washington PINE | =4.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0014 is classified as a high severity vulnerability due to its potential to allow remote command execution.
To fix CVE-2002-0014, upgrade to Pine version 4.44 or later, which addresses this vulnerability.
CVE-2002-0014 affects Pine versions 4.20, 4.21, 4.30, and 4.33 from University of Washington.
CVE-2002-0014 allows attackers to execute arbitrary commands by exploiting URL-handling through shell metacharacters.
Yes, using a vulnerable version of Pine can lead to remote code execution, risking compromise of your system.