Qualcomm Eudora MIME Attachment Spoofing Vulnerability
BID:10671
Info
Qualcomm Eudora MIME Attachment Spoofing Vulnerability
| Bugtraq ID: | 10671 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2004 12:00AM |
| Updated: | Jul 06 2004 12:00AM |
| Credit: | [email protected] (Paul Szabo) disclosed this vulnerability. |
| Vulnerable: |
Qualcomm Eudora 6.2 .0.7 Beta Qualcomm Eudora 6.2 .0.14 Qualcomm Eudora 6.1.2 Qualcomm Eudora 6.1.1 |
| Not Vulnerable: | |
Discussion
Qualcomm Eudora MIME Attachment Spoofing Vulnerability
It is reported that Eudora is susceptible to a MIME attachment spoofing vulnerability.
A user of Eudora could potentially be tricked into unknowingly sending sensitive files as attachments to forwarded email containing malicious MIME attachments.
Eudora version 6.1.2 for Windows was reported by the vendor to be fixed, but Paul Szabo disclosed an untested proof-of-concept exploit to demonstrate that the vulnerability still reportedly exists.
It is reported that Eudora is susceptible to a MIME attachment spoofing vulnerability.
A user of Eudora could potentially be tricked into unknowingly sending sensitive files as attachments to forwarded email containing malicious MIME attachments.
Eudora version 6.1.2 for Windows was reported by the vendor to be fixed, but Paul Szabo disclosed an untested proof-of-concept exploit to demonstrate that the vulnerability still reportedly exists.
Exploit / POC
Qualcomm Eudora MIME Attachment Spoofing Vulnerability
A proof-of-concept exploit was provided by [email protected] (Paul Szabo). A proof of concept for Eudora 6.2.0.7 Beta was provided by [email protected] (Paul Szabo) as well.
A proof of concept for Eudora 6.2.0.14 was provided by [email protected] (Paul Szabo).
A proof-of-concept exploit was provided by [email protected] (Paul Szabo). A proof of concept for Eudora 6.2.0.7 Beta was provided by [email protected] (Paul Szabo) as well.
A proof of concept for Eudora 6.2.0.14 was provided by [email protected] (Paul Szabo).
Solution / Fix
Qualcomm Eudora MIME Attachment Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Qualcomm Eudora MIME Attachment Spoofing Vulnerability
References:
References:
- EUDORA FOR WINDOWS, VERSION 6.1.2 -- RELEASE NOTES (Qualcomm)
- Eudora Product Homepage (Qualcomm)
- Eudora 6.1.2 attachment spoof ([email protected] (Paul Szabo))
- Eudora 6.2 attachment spoof (Paul Szabo
) - Eudora 6.2.0.7 attachment spoof (Paul Szabo
)