Pine Environment Variable Expansion in URLS Vulnerability
BID:810
Info
Pine Environment Variable Expansion in URLS Vulnerability
| Bugtraq ID: | 810 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 1999 12:00AM |
| Updated: | Nov 18 1999 12:00AM |
| Credit: | First posted to BugTraq by Jim Hebert <[email protected]> on Nov 18, 1999. |
| Vulnerable: |
University of Washington Pine 4.21 University of Washington Pine 4.20 |
| Not Vulnerable: | |
Exploit / POC
Pine Environment Variable Expansion in URLS Vulnerability
See discussion.
See discussion.
Solution / Fix
Pine Environment Variable Expansion in URLS Vulnerability
Solution:
Caldera Linux:
Obtain the rpm from:
ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.3/current/RPMS/
To install the rpm.
rpm -U pine-4.21-1.i386.rpm
the SecurityFocus staff are not ware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Caldera Linux:
Obtain the rpm from:
ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.3/current/RPMS/
To install the rpm.
rpm -U pine-4.21-1.i386.rpm
the SecurityFocus staff are not ware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Pine Environment Variable Expansion in URLS Vulnerability
References:
References:
- Pine Homepage/Information (University of Washington)