[7002] in bugtraq
Re: another remote pine vunerability
daemon@ATHENA.MIT.EDU (Jason H. Reeves)
Fri Jun 19 19:59:40 1998
Date: Thu, 18 Jun 1998 18:39:39 -0500
Reply-To: "Jason H. Reeves" <jhr@COMP.UARK.EDU>
From: "Jason H. Reeves" <jhr@COMP.UARK.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <Pine.LNX.3.96.980617164950.707A-100000@ppp2-cst105.warszawa.tpnet.pl>
On Wed, 17 Jun 1998, Michal Zalewski wrote:
> Recently I found silly remote overflow in pine. It's so simple there's no
> need to describe it:
I tried this on pine 3.96 on Solaris 2.5.1 and had no problems. I
used your bogus address, put it as the From: field in a bogus test
message, and appended it to /var/mail/jhr and tried to read it. I read it
without any problems.
----------------------------------------------------------------------------><>
Jason H. Reeves (KC5TTQ) jason.reeves@mail.state.ar.us
Arkansas Department of Information Systems Little Rock, AR
<><----------------------------------------------------------------------------