First published: Wed Dec 11 2002(Updated: )
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington PINE | =4.0.2 | |
University of Washington PINE | =4.30 | |
University of Washington PINE | =4.21 | |
University of Washington PINE | =4.10 | |
University of Washington PINE | =3.98 | |
University of Washington PINE | =4.0.4 | |
University of Washington PINE | =4.44 | |
University of Washington PINE | =4.33 | |
University of Washington PINE | =4.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1320 allows remote attackers to trigger a denial of service, causing Pine to core dump and fail to restart.
CVE-2002-1320 affects Pine versions 4.44 and earlier, including 4.0.2, 4.10, 4.21, 4.30, 4.33, 4.20, and 3.98.
To address CVE-2002-1320, upgrade Pine to a version later than 4.44 that contains the relevant security patches.
While CVE-2002-1320 can cause a denial of service, its severity level should be evaluated according to the specific environment and usage of Pine.
CVE-2002-1320 can be exploited by sending an email with a From header that contains an excessive number of quotation marks.