Back to Database
Status published
Critical
CVE-2000-0352
Pine before version 4.21 does not properly filter shell metacharacters...
Vulnerability Description
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2000-0352
Credits & Attribution
No credits recorded in the NVD database.
References
- ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-036.0.txt
- http://www.securityfocus.com/bid/810
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.9911171818220.12375-100000%40ray.compu-aid.com
- http://www.novell.com/linux/security/advisories/suse_security_announce_36.html
More from university of washington
View All →CVE-2008-5514
Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines...
Medium
4.3
CVE-2008-5006
smtp.c in the c-client library in University of Washington IMAP...
Medium
5
CVE-2008-5005
Multiple stack-based buffer overflows in (1) University of Washington IMAP...
Critical
10
CVE-2006-1394
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI...
Medium
4.3
CVE-2006-1393
Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application...
Medium
4.3
Affected Vendor
university of washington
View all reports →Affected Software
pine
Vulnerable Versions:
4.20, 4.21
Timeline
Official Publish:
July 12th, 2000
Last Modified:
August 8th, 2024
Added to House:
July 17th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.