Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: pine
Date: Mon, 02 Dec 2002 14:16:44
Message-Id: 20021202133919.A738333762@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200212-1
6 - - --------------------------------------------------------------------
7
8 PACKAGE : pine
9 SUMMARY : remote DOS
10 DATE    : 2002-12-02 13:12 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 An attacker can send a fully legal email message with a crafted
16 From-header and thus forcing pine to core dump on startup.
17 The only way to launch pine is manually removing the bad message
18 either directly from the spool, or from another MUA. Until the
19 message has been removed or edited there is no way of accessing
20 the INBOX using pine.
21
22 Read the full advisory at
23 http://marc.theaimsgroup.com/?l=bugtraq&m=103668430620531&w=2
24
25 SOLUTION
26
27 It is recommended that all Gentoo Linux users who are running
28 net-mail/pine-4.44-r5 and earlier update their systems as follows:
29
30 emerge rsync
31 emerge pine
32 emerge clean
33
34 - - --------------------------------------------------------------------
35 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
36 raker@g.o
37 - - --------------------------------------------------------------------
38 -----BEGIN PGP SIGNATURE-----
39 Version: GnuPG v1.2.1 (GNU/Linux)
40
41 iD8DBQE962KFfT7nyhUpoZMRAuXRAJ98j+FOcW1T2+ltJNPhj2lPc7dU/gCfb8IK
42 jEpRPKyGYvhU28yicSxYzCs=
43 =E178
44 -----END PGP SIGNATURE-----