Pine Environment Variable URL Shell Interpreting Vulnerability
BID:3815
Info
Pine Environment Variable URL Shell Interpreting Vulnerability
| Bugtraq ID: | 3815 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2002 12:00AM |
| Updated: | Jan 05 2002 12:00AM |
| Credit: | This vulnerability was originally discovered by Jim Hebert <[email protected]> on November 18, 1999, and was rediscovered by zen-parse <[email protected]> October 20, 2001. It was reannounced to Bugtraq on January 5, 2002. |
| Vulnerable: |
University of Washington Pine 4.33 University of Washington Pine 4.30 University of Washington Pine 4.21 University of Washington Pine 4.20 |
| Not Vulnerable: |
University of Washington Pine 4.44 |
Discussion
Pine Environment Variable URL Shell Interpreting Vulnerability
Pine is a freely available, open source email client. It is distributed and maintained by Washington University.
A problem with Pine has been discovered that could make it possible to execute arbitrary commands. The problem is in the handling of URLs with encapsulated environment variables.
The problem is in the handling of URLs with environment variables in them. An email sent to a user with an encoded environment variable and command in the URL could be used to execute the encoded command with the privileges of the user receiving the mail. This could make it possible to perform one of any number of commands as the user receiving the mail. This vulnerability is only present in email clients that have had a URL handler configured.
Pine is a freely available, open source email client. It is distributed and maintained by Washington University.
A problem with Pine has been discovered that could make it possible to execute arbitrary commands. The problem is in the handling of URLs with encapsulated environment variables.
The problem is in the handling of URLs with environment variables in them. An email sent to a user with an encoded environment variable and command in the URL could be used to execute the encoded command with the privileges of the user receiving the mail. This could make it possible to perform one of any number of commands as the user receiving the mail. This vulnerability is only present in email clients that have had a URL handler configured.
Exploit / POC
Pine Environment Variable URL Shell Interpreting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Pine Environment Variable URL Shell Interpreting Vulnerability
Solution:
HP Secure OS software for Linux 1.0 users should download and apply the Red Hat RPMs.
Vendor fixes available:
University of Washington Pine 4.20
University of Washington Pine 4.21
University of Washington Pine 4.30
University of Washington Pine 4.33
Solution:
HP Secure OS software for Linux 1.0 users should download and apply the Red Hat RPMs.
Vendor fixes available:
University of Washington Pine 4.20
-
University of Washington Pine 4.44
ftp://ftp.cac.washington.edu/pine/pine.tar.Z
University of Washington Pine 4.21
-
Conectiva pico-4.44L-1U50_1cl.i386.rpm
Release 5.0
ftp://atualizacoes.conectiva.com.br/5.0/i386/pico-4.44L-1U50_1cl.i386. rpm -
Conectiva pico-4.44L-1U50_1cl.i386.rpm
ECommerce Release
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/pico-4. 44L-1U50_1cl.i386.rpm -
Conectiva pico-4.44L-1U50_1cl.i386.rpm
Graficas Release
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/pico-4.4 4L-1U50_1cl.i386.rpm -
Conectiva pico-4.44L-1U51_1cl.i386.rpm
Release 5.1
ftp://atualizacoes.conectiva.com.br/5.1/i386/pico-4.44L-1U51_1cl.i386. rpm -
Conectiva pico-4.44L-1U70_1cl.i386.rpm
Release 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/pico-4.44L-1U70_1cl.i386. rpm -
Conectiva pilot-4.44L-1U50_1cl.i386.rpm
Release 5.0
ftp://atualizacoes.conectiva.com.br/5.0/i386/pilot-4.44L-1U50_1cl.i386 .rpm -
Conectiva pilot-4.44L-1U50_1cl.i386.rpm
ECommerce Release
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/pilot-4 .44L-1U50_1cl.i386.rpm -
Conectiva pilot-4.44L-1U50_1cl.i386.rpm
Graficas Release
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/pilot-4. 44L-1U50_1cl.i386.rpm -
Conectiva pilot-4.44L-1U51_1cl.i386.rpm
Release 5.1
ftp://atualizacoes.conectiva.com.br/5.1/i386/pilot-4.44L-1U51_1cl.i386 .rpm -
Conectiva pilot-4.44L-1U70_1cl.i386.rpm
Release 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/pilot-4.44L-1U70_1cl.i386 .rpm -
Conectiva pine-4.44L-1U50_1cl.i386.rpm
Release 5.0
ftp://atualizacoes.conectiva.com.br/5.0/i386/pine-4.44L-1U50_1cl.i386. rpm -
Conectiva pine-4.44L-1U50_1cl.i386.rpm
ECommerce Release
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/pine-4. 44L-1U50_1cl.i386.rpm -
Conectiva pine-4.44L-1U50_1cl.i386.rpm
Graficas Release
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/pine-4.4 4L-1U50_1cl.i386.rpm -
Conectiva pine-4.44L-1U51_1cl.i386.rpm
Release 5.1
ftp://atualizacoes.conectiva.com.br/5.1/i386/pine-4.44L-1U51_1cl.i386. rpm -
Conectiva pine-4.44L-1U70_1cl.i386.rpm
Release 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/pine-4.44L-1U70_1cl.i386. rpm -
Red Hat pine-4.44-1.62.0.alpha.rpm
Release 6.2
ftp://updates.redhat.com/6.2/en/os/alpha/pine-4.44-1.62.0.alpha.rpm -
Red Hat pine-4.44-1.62.0.i386.rpm
Release 6.2
ftp://updates.redhat.com/6.2/en/os/i386/pine-4.44-1.62.0.i386.rpm -
Red Hat pine-4.44-1.62.0.sparc.rpm
Release 6.2
ftp://updates.redhat.com/6.2/en/os/sparc/pine-4.44-1.62.0.sparc.rpm -
Red Hat pine-4.44-1.70.0.alpha.rpm
Release 7.0
ftp://updates.redhat.com/7.0/en/os/alpha/pine-4.44-1.70.0.alpha.rpm -
Red Hat pine-4.44-1.70.0.i386.rpm
Release 7.0
ftp://updates.redhat.com/7.0/en/os/i386/pine-4.44-1.70.0.i386.rpm -
University of Washington Pine 4.44
ftp://ftp.cac.washington.edu/pine/pine.tar.Z
University of Washington Pine 4.30
-
University of Washington Pine 4.44
ftp://ftp.cac.washington.edu/pine/pine.tar.Z
University of Washington Pine 4.33
-
FreeBSD ports-4 pine-4.44.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/mail/pi ne-4.44.tgz -
Red Hat pine-4.44-1.71.0.alpha.rpm
Release 7.1
ftp://updates.redhat.com/7.1/en/os/alpha/pine-4.44-1.71.0.alpha.rpm -
Red Hat pine-4.44-1.71.0.i386.rpm
Release 7.1
ftp://updates.redhat.com/7.1/en/os/i386/pine-4.44-1.71.0.i386.rpm -
Red Hat pine-4.44-1.71.0.ia64.rpm
Release 7.1
ftp://updates.redhat.com/7.1/en/os/ia64/pine-4.44-1.71.0.ia64.rpm -
Red Hat pine-4.44-1.72.0.i386.rpm
Release 7.2
ftp://updates.redhat.com/7.2/en/os/i386/pine-4.44-1.72.0.i386.rpm -
Red Hat pine-4.44-1.72.0.ia64.rpm
Release 7.2
ftp://updates.redhat.com/7.2/en/os/ia64/pine-4.44-1.72.0.ia64.rpm -
Red Hat pine-4.44-1.72.0.s390.rpm
S/390
ftp://updates.redhat.com/7.2/en/os/s390/pine-4.44-1.72.0.s390.rpm -
University of Washington Pine 4.44
ftp://ftp.cac.washington.edu/pine/pine.tar.Z
References
Pine Environment Variable URL Shell Interpreting Vulnerability
References:
References: