CVE-2002-2325: Input Validation
Published Dec 31, 2002
·Updated
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.
Affected Software
5 affected components
University of Washington pine=4.30
University of Washington pine=4.21
University of Washington pine=4.44
University of Washington pine=4.33
University of Washington pine=4.20
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 26, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2325?
CVE-2002-2325 is classified as a moderate severity vulnerability that can lead to a denial of service.
2
How do I fix CVE-2002-2325?
To fix CVE-2002-2325, upgrade to a version of Pine later than 4.44.
3
Which versions of Pine are affected by CVE-2002-2325?
Versions of Pine from 4.20 to 4.44 are affected by CVE-2002-2325.
4
What type of attack does CVE-2002-2325 exploit?
CVE-2002-2325 exploits a vulnerability that allows remote attackers to crash the Pine email client.
5
What is the primary impact of CVE-2002-2325?
The primary impact of CVE-2002-2325 is a denial of service attack causing the email client to crash.