CVE-2000-0353

Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:university_of_washington:pine:3.98:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.0:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.2:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.10:*:*:*:*:*:*:*

History

20 Nov 2024, 23:32

Type Values Removed Values Added
References () http://www.novell.com/linux/security/advisories/pine_update_announcement.html - () http://www.novell.com/linux/security/advisories/pine_update_announcement.html -
References () http://www.novell.com/linux/security/advisories/suse_security_announce_6.html - () http://www.novell.com/linux/security/advisories/suse_security_announce_6.html -
References () http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html - Exploit, Patch, Vendor Advisory () http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html - Exploit, Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/1247 - () http://www.securityfocus.com/bid/1247 -

Information

Published : 1999-06-28 04:00

Updated : 2024-11-20 23:32


NVD link : CVE-2000-0353

Mitre link : CVE-2000-0353

CVE.ORG link : CVE-2000-0353


JSON object : View

Products Affected

university_of_washington

  • pine