85857 2002-12-02 18:52 /45 rader/ Daniel Ahlberg <aliz@gentoo.org> Importerad: 2002-12-02 18:52 av Brevbäraren Extern mottagare: bugtraq@securityfocus.com Mottagare: Bugtraq (import) <2608> Ärende: GLSA: pine ------------------------------------------------------------ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200212-1 - - -------------------------------------------------------------------- PACKAGE : pine SUMMARY : remote DOS DATE : 2002-12-02 13:12 UTC EXPLOIT : remote - - -------------------------------------------------------------------- An attacker can send a fully legal email message with a crafted From-header and thus forcing pine to core dump on startup. The only way to launch pine is manually removing the bad message either directly from the spool, or from another MUA. Until the message has been removed or edited there is no way of accessing the INBOX using pine. Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=103668430620531&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running net-mail/pine-4.44-r5 and earlier update their systems as follows: emerge rsync emerge pine emerge clean - - -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz raker@gentoo.org - - -------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE962KFfT7nyhUpoZMRAuXRAJ98j+FOcW1T2+ltJNPhj2lPc7dU/gCfb8IK jEpRPKyGYvhU28yicSxYzCs= =E178 -----END PGP SIGNATURE----- (85857) /Daniel Ahlberg <aliz@gentoo.org>/----------