Bugtraq mailing list archives

Re: another remote pine vunerability


From: jhr () COMP UARK EDU (Jason H. Reeves)
Date: Thu, 18 Jun 1998 18:39:39 -0500


On Wed, 17 Jun 1998, Michal Zalewski wrote:

Recently I found silly remote overflow in pine. It's so simple there's no
need to describe it:

        I tried this on pine 3.96 on Solaris 2.5.1 and had no problems.  I
used your bogus address, put it as the From: field in a bogus test
message, and appended it to /var/mail/jhr and tried to read it.  I read it
without any problems.

----------------------------------------------------------------------------><>
Jason H. Reeves (KC5TTQ)                        jason.reeves () mail state ar us
Arkansas Department of Information Systems      Little Rock, AR
<><----------------------------------------------------------------------------



Current thread: