PGP4Pine Long Message Line Buffer Overflow Vulnerability
BID:7071
Info
PGP4Pine Long Message Line Buffer Overflow Vulnerability
| Bugtraq ID: | 7071 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2003 12:00AM |
| Updated: | Mar 12 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Eric AUGE <[email protected]>. |
| Vulnerable: |
Holger Lamm pgp4pine 1.76 Holger Lamm pgp4pine 1.75.6 |
| Not Vulnerable: | |
Discussion
PGP4Pine Long Message Line Buffer Overflow Vulnerability
A vulnerability has been discovered in PGP4Pine. The problem occurs when parsing an email message for PGP data. Due to insufficient bounds checking, when processing lines of excessive length, a buffer may be overrun. This would result in sensitive locations in memory being overwritten with data supplied in the message.
Successful exploitation of this issue may allow a remote attacker to execute arbitrary commands on a target system. All instructions executed would be run with the privileges of the users running the software.
This issue affects pgp4pine version 1.76 and earlier.
A vulnerability has been discovered in PGP4Pine. The problem occurs when parsing an email message for PGP data. Due to insufficient bounds checking, when processing lines of excessive length, a buffer may be overrun. This would result in sensitive locations in memory being overwritten with data supplied in the message.
Successful exploitation of this issue may allow a remote attacker to execute arbitrary commands on a target system. All instructions executed would be run with the privileges of the users running the software.
This issue affects pgp4pine version 1.76 and earlier.