URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pine | University_of_washington | 4.20 (including) | 4.20 (including) |
| Pine | University_of_washington | 4.21 (including) | 4.21 (including) |
| Pine | University_of_washington | 4.30 (including) | 4.30 (including) |
| Pine | University_of_washington | 4.33 (including) | 4.33 (including) |
| Red Hat Linux 6.2 | RedHat | * | |
| Red Hat Linux 7.0 | RedHat | * | |
| Red Hat Linux 7.1 | RedHat | * | |
| Red Hat Linux 7.2 | RedHat | * |