Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pine | University_of_washington | 4.21 (including) | 4.21 (including) |
| Pine | University_of_washington | 4.30 (including) | 4.30 (including) |
| Pine | University_of_washington | 4.33 (including) | 4.33 (including) |
| Pine | University_of_washington | 4.44 (including) | 4.44 (including) |