CVE-2003-0721Improper Validation of Array Index in Pine

Severity
7.5HIGHNVD
EPSS
2.8%
top 13.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateApr 29

Description

Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDwashington/pine< 4.58
debiandebian/alpine

Patches

🔴Vulnerability Details

1
GHSA
GHSA-852c-jm45-g4vc: Integer signedness error in rfc2231_get_param from strings2022-04-29

📋Vendor Advisories

2
Red Hat
security flaw2003-09-10
Debian
CVE-2003-0721: alpine - Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58...2003

📐Framework References

1
CWE
Improper Validation of Array Index

💬Community

1
Bugzilla
CVE-2003-0721 security flaw2018-08-16
CVE-2003-0721 — Improper Validation of Array Index | cvebase