Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
http://www.securityfocus.com/bid/810
http://www.novell.com/linux/security/advisories/suse_security_announce_36.html