Qualcomm Eudora File Attachment Vulnerability
BID:2616
Info
Qualcomm Eudora File Attachment Vulnerability
| Bugtraq ID: | 2616 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2001 12:00AM |
| Updated: | Apr 18 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Magnus Bodin <[email protected]> on April 18, 2001. |
| Vulnerable: |
Qualcomm Eudora 5.1 Qualcomm Eudora 5.0.2 |
| Not Vulnerable: | |
Discussion
Qualcomm Eudora File Attachment Vulnerability
If an attacker composed an email with the body of the message containing the path to a known file residing on the target recipient's system, Eudora will automatically attach the file if the recipient forwards the message, compromising confidentiality of the target and potentially supplying an attacker with information which could be used to further breach the security of the vulnerable system.
If an attacker composed an email with the body of the message containing the path to a known file residing on the target recipient's system, Eudora will automatically attach the file if the recipient forwards the message, compromising confidentiality of the target and potentially supplying an attacker with information which could be used to further breach the security of the vulnerable system.
Exploit / POC
Qualcomm Eudora File Attachment Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Qualcomm Eudora File Attachment Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.