First published: Tue Dec 31 2002(Updated: )
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University of Washington PINE | =4.30 | |
University of Washington PINE | =4.21 | |
University of Washington PINE | =4.44 | |
University of Washington PINE | =4.33 | |
University of Washington PINE | =4.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2325 is classified as a moderate severity vulnerability that can lead to a denial of service.
To fix CVE-2002-2325, upgrade to a version of Pine later than 4.44.
Versions of Pine from 4.20 to 4.44 are affected by CVE-2002-2325.
CVE-2002-2325 exploits a vulnerability that allows remote attackers to crash the Pine email client.
The primary impact of CVE-2002-2325 is a denial of service attack causing the email client to crash.