Pine 4.x - 'From:' Heap Corruption
Author: lsjoberg
type: dos
platform: linux
port:
date_added: 2002-11-07
date_updated: 2017-11-07
verified: 1
codes: CVE-2002-1320;OSVDB-6948
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/6120/info
A heap corruption may occur when Pine receives an email message containing a particularly crafted "From:" address. Though the address is RFC compliant, Pine reportedly fails to parse it correctly, resulting in a core dump. Execution of arbitrary code may be possible.
"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\"\""@host.fubar