From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-out.kivex.com ([204.177.32.18]) by speech.braille.uwo.ca with esmtp (Exim 3.32 #1 (Debian)) id 16OgVK-00059A-00 for ; Thu, 10 Jan 2002 09:48:30 -0500 Received: from ccrawford.acb.org ([216.51.9.68]) by smtp-out.kivex.com (8.8.8/8.8.7-KIVEX) with ESMTP id JAA19530 for ; Thu, 10 Jan 2002 09:49:08 -0500 (EST) Message-Id: <5.1.0.14.2.20020103105858.02282140@198.144.194.210> X-Sender: ccrawford@198.144.194.210 X-Mailer: QUALCOMM Windows Eudora Version 5.1 Date: Thu, 03 Jan 2002 10:59:56 -0500 To: speakup@braille.uwo.ca From: Charles Crawford Subject: New Pine release In-Reply-To: <030401c19973$5d43d5a0$6401a8c0@alex1.va.home.com> References: Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed Sender: speakup-admin@braille.uwo.ca Errors-To: speakup-admin@braille.uwo.ca X-BeenThere: speakup@braille.uwo.ca X-Mailman-Version: 2.0.7 Precedence: bulk Reply-To: speakup@braille.uwo.ca List-Help: List-Post: List-Subscribe: , List-Id: Speakup is a screen review system for Linux. List-Unsubscribe: , List-Archive: In case you did not see this. Subject: Pine 4.44 now available This note is to announce the availability of the Pine Message System version 4.44. The purpose of this release is to fix a security bug with the treatment of quotes in the URL-handling code. The bug allows a malicious sender to embed commands in a URL. This bug is present in all versions of UNIX Pine. There is no vulnerability from this bug in PC-Pine. The release notes are available from within Pine ("R" command off the Main Menu) and via http://www.washington.edu/pine/changes.html and ftp://ftp.cac.washington.edu/pine/docs/ Source for the latest Pine release is available in: ftp://ftp.cac.washington.edu/pine/pine.tar.Z and ftp://ftp.cac.washington.edu/pine/pine.tar.gz Precompiled binaries for the various systems we have direct access to are available in: ftp://ftp.cac.washington.edu/pine/unix-bin and ftp://ftp.cac.washington.edu/pine/unix-bin-compressed The corresponding PC-Pine distribution is available in: ftp://ftp.cac.washington.edu/pine/pcpine/pm444w32.zip As with all Pine releases, it is important that you carefully test and determine for yourself that it performs suitably in your environment before placing Pine into production use. The Pine Development Team --