Suse 5.3 - 6.3: Security hole in Pine < 4.21
Summary
-----BEGIN PGP SIGNED MESSAGE-----
_____________________________________________________________________________
SuSE Security Announcement
Package: pine-4.10
Date: Wed Dec 15 18:32:56 MET 1999
Affected SuSE versions: 5.3 - 6.3
Vulnerability Type: remote command execution
SuSE default package: no
Other affected systems: all unix systems using the pine prior 4.21
______________________________________________________________________________
A security hole was discovered in the package mentioned above.
Please update as soon as possible or disable the service if you are using
this software on your SuSE Linux installation(s).
Other Linux distributions or operating systems might be affected as
well, please contact your vendor for information about this issue.
Please note, that that we provide this information on an "as-is" basis only.
There is no warranty whatsoever and no liability for any direct, indirect or
incidental damage arising from this information or the installation of
the update package.
_____________________________________________________________________________
1. Problem Description
The pine mail agent doesn't filter special shell characters in URLs.
2. Impact
An attacker can trick a user using pine to executing shell commands
by sending an email with malicious formatted URL embedded in it.
3. Solution
Update the package from our FTP server.
______________________________________________________________________________
Please verify these md5 checksums of the updates before installing:
bbfa5cb60f8f5c29f18bb14744071953 pine-4.21-11.alpha.rpm (6.1, AXP)
b2980666737dd4a4db46e1c3d3c7aea0 pine-4.21-11.i386.rpm (5.3, x86)
d70ef356f093683c85cba53cc573c1b5 pine-4.10-40.i386.rpm (6.0, x86)
7286ed1525c94a7b36c7a2c68ccb4890 pine-4.21-11.i386.rpm (6.1, x86)
159d028af3aaca959cada37c7a68cc07 pine-4.21-11.i386.rpm (6.2, x86)
df36f3e6da96dc4c6a5811302e5b926f pine-4.21-13.i386.rpm (6.3, x86)
______________________________________________________________________________
You can find updates on our ftp-Server:
or try the following web pages for a list of mirrors:
http://www.suse.de/de/support/download/ftp/inland.html
http://www.suse.de/de/support/download/ftp/ausland.html
or
http://www.suse.de/en/support/download/ftp/germ_mirrors.html
http://www.suse.de/en/support/download/ftp/int_mirrors.html
Our webpage for patches:
http://www.suse.de/de/support/download/updates/index.html
or
http://www.suse.de/en/support/download/updates/index.html
Our webpage for security announcements:
http://www.suse.de/security
If you want to report vulnerabilities, please contact
security@suse.de
______________________________________________________________________________
SuSE has got two free security mailing list services to which any
interested party may subscribe:
suse-security@suse.com - moderated and for general/linux/SuSE
security discussions. All SuSE security
announcements are send to this list.
suse-security-announce@suse.com - SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent
to this list.
To subscribe to the list, send a message to:
References