CVE-2000-0909
Medium
Elevated severity or exploit probability.
CVSS base
7.5
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS — probability of exploitation (30 days)
11.5%
95.9th percentile
CISA KEV
Not listed
Weakness / dates
—
Published 2000-12-19 · modified 2026-09-23
CVSS breakdown
AV:N/AC:L/Au:N/C:P/I:P/A:P
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Authentication | N | None |
| Confidentiality | P | Partial |
| Integrity | P | Partial |
| Availability | P | Partial |
Timeline
- 2000-12-19 — Published (NVD)
- 2026-09-23 — Last modified (NVD)
Description
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
Affected
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:59.pine.asc
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html
- http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3
- http://www.redhat.com/support/errata/RHSA-2000-102.html
- http://www.securityfocus.com/archive/1/84901
- exploit http://www.securityfocus.com/bid/1709
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5283
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:59.pine.asc
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html
- http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3
- http://www.redhat.com/support/errata/RHSA-2000-102.html
- http://www.securityfocus.com/archive/1/84901
- exploit http://www.securityfocus.com/bid/1709
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5283