CVE-2003-0721: Out-of-bounds Read
Integer signedness error in rfc2231getparam from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0721?
CVE-2003-0721 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2003-0721?
To fix CVE-2003-0721, update PINE to version 4.58 or later.
What versions of PINE are affected by CVE-2003-0721?
PINE versions prior to 4.58, including 4.0.2, 4.56, 4.50, 4.30, 4.21, 4.10, 3.98, 4.53, 4.52, 4.33, 4.44, and 4.0.4, are affected by CVE-2003-0721.
Can CVE-2003-0721 lead to data compromise?
Yes, CVE-2003-0721 can lead to data compromise through remote code execution if exploited.
What should I do if I cannot update PINE due to compatibility issues related to CVE-2003-0721?
If updating PINE is not an option, consider implementing network security measures such as email filtering and monitoring to mitigate the risk associated with CVE-2003-0721.