5
CVSSv2

CVE-2002-1320

Published: 11/12/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Pine 4.44 and previous versions allows remote malicious users to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").

Vulnerable Product Search on Vulmon Subscribe to Product

university of washington pine 4.10

university of washington pine 4.20

university of washington pine 3.98

university of washington pine 4.33

university of washington pine 4.44

university of washington pine 4.0.2

university of washington pine 4.0.4

university of washington pine 4.21

university of washington pine 4.30

Exploits

source: wwwsecurityfocuscom/bid/6120/info A heap corruption may occur when Pine receives an email message containing a particularly crafted "From:" address Though the address is RFC compliant, Pine reportedly fails to parse it correctly, resulting in a core dump Execution of arbitrary code may be possible "\"\"\"\"\"\"\"\"\"\"\"\"\"\ ...