CVE-2002-2325

The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:university_of_washington:pine:4.20:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.21:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.30:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.33:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.44:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/284086 - () http://online.securityfocus.com/archive/1/284086 -
References () http://www.iss.net/security_center/static/9668.php - Patch () http://www.iss.net/security_center/static/9668.php - Patch
References () http://www.securityfocus.com/bid/5301 - Exploit () http://www.securityfocus.com/bid/5301 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2325

Mitre link : CVE-2002-2325

CVE.ORG link : CVE-2002-2325


JSON object : View

Products Affected

university_of_washington

  • pine
CWE
CWE-20

Improper Input Validation