* GLSA: pine
@ 2002-12-02 13:39 Daniel Ahlberg
0 siblings, 0 replies; only message in thread
From: Daniel Ahlberg @ 2002-12-02 13:39 UTC (permalink / raw
To: gentoo-announce
[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain, Size: 1421 bytes --]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-1
- - --------------------------------------------------------------------
PACKAGE : pine
SUMMARY : remote DOS
DATE : 2002-12-02 13:12 UTC
EXPLOIT : remote
- - --------------------------------------------------------------------
An attacker can send a fully legal email message with a crafted
From-header and thus forcing pine to core dump on startup.
The only way to launch pine is manually removing the bad message
either directly from the spool, or from another MUA. Until the
message has been removed or edited there is no way of accessing
the INBOX using pine.
Read the full advisory at
http://marc.theaimsgroup.com/?l=bugtraq&m=103668430620531&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running
net-mail/pine-4.44-r5 and earlier update their systems as follows:
emerge rsync
emerge pine
emerge clean
- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
raker@gentoo.org
- - --------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQE962KFfT7nyhUpoZMRAuXRAJ98j+FOcW1T2+ltJNPhj2lPc7dU/gCfb8IK
jEpRPKyGYvhU28yicSxYzCs=
=E178
-----END PGP SIGNATURE-----
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2002-12-02 14:16 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-12-02 13:39 GLSA: pine Daniel Ahlberg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox