SMTP: Pine Blank MIME Boundary Exception

This signature detects attempts to exploit a known vulnerability in the Pine E-mail client. Pine versions 4.4 and earlier are vulnerable. Attackers can send MIME-encoded e-mails with a blank boundary field to crash the mail client.

Extended Description

Pine is an open source mail user agent distributed by the University of Washington. It is freely available for Unix, Linux, and Microsoft Operating Systems. When a mail is received by pine that contains MIME content, and the value of the MIME boundary is blank, pine becomes unstable. This vulnerability has been discovered to cause a core dump in the pine client, and could be used to deny service to legitimate users of the client.

Affected Products

University_of_washington pine

References

BugTraq: 5301

URL: http://securityvulns.com/docs3258.html

Short Name
SMTP:EXPLOIT:PINE-BOUNDARY
Severity
Warning
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
Blank Boundary Exception MIME Pine bid:5301
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

University_of_washington

Found a potential security threat?