CVE-2002-1903: Medium severity University of Washington pine vulnerability
Published Dec 31, 2002
·Updated
Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.
Affected Software
4 affected components
University of Washington pine=4.21
University of Washington pine=4.30
University of Washington pine=4.33
University of Washington pine=4.44
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1903?
CVE-2002-1903 is considered a moderate severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2002-1903?
To fix CVE-2002-1903, upgrade Pine to a version later than 4.44 that does not include Unix usernames in email headers.
3
What systems are affected by CVE-2002-1903?
CVE-2002-1903 affects Pine versions 4.21 through 4.44.
4
How does CVE-2002-1903 expose sensitive information?
CVE-2002-1903 allows remote attackers to potentially read Unix usernames and UIDs from the Sender and X-Sender headers.
5
When was CVE-2002-1903 reported?
CVE-2002-1903 was reported in the year 2002.