Vulnerability Description
Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| University Of Washington | Pine | 3.98 |
References
- http://www.novell.com/linux/security/advisories/pine_update_announcement.html
- http://www.novell.com/linux/security/advisories/suse_security_announce_6.html
- http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.htmlExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/1247
- http://www.novell.com/linux/security/advisories/pine_update_announcement.html
- http://www.novell.com/linux/security/advisories/suse_security_announce_6.html
- http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.htmlExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/1247
FAQ
What is CVE-2000-0353?
CVE-2000-0353 is a vulnerability with a CVSS score of 10.0 (HIGH). Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
How severe is CVE-2000-0353?
CVE-2000-0353 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0353?
Check the references section above for vendor advisories and patch information. Affected products include: University Of Washington Pine.