Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-2325Improper Input Validation in OF Washington Pine

Severity
7.8HIGHNVD
EPSS
6.3%
top 9.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 31
Latest updateApr 30

Description

The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r8h8-frgh-vvhh: The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 42022-04-30
CVEList
CVE-2002-2325: The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 42007-10-26

💥Exploits & PoCs

1
Exploit-DB
Pine 4.x - Empty MIME Boundary Denial of Service2002-07-24
CVE-2002-2325 — Improper Input Validation | cvebase