PT-2003-1817 · Washington University · Pine

Zen-Parse

·

Publicado

2003-09-12

·

Atualizado

2024-02-09

·

CVE-2003-0721

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PINE versions prior to 4.58
Description: The issue is related to an integer signedness error in the rfc2231 get param function from strings.c. This error allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.
Recommendations: For versions prior to 4.58, update to version 4.58 or later to resolve the issue. As a temporary workaround, consider restricting access to emails that could potentially exploit this issue until a patch is applied.

Exploit

Correção

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-0721

Produtos afetados

Pine