CVE

CVE-2002-1903

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2002
Last modified:
05/09/2008

Description

Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:university_of_washington:pine:4.21:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.30:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.33:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:pine:4.44:*:*:*:*:*:*:*