Qualcomm Eudora Hidden Attachment Execution Vulnerability
BID:2796
Info
Qualcomm Eudora Hidden Attachment Execution Vulnerability
| Bugtraq ID: | 2796 |
| Class: | Unknown |
| CVE: |
CVE-2001-1326 |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered and posted to Bugtraq by [email protected] <[email protected]> on May 29, 2001. |
| Vulnerable: |
Qualcomm Eudora 5.1.1 Qualcomm Eudora 5.1 |
| Not Vulnerable: | |
Discussion
Qualcomm Eudora Hidden Attachment Execution Vulnerability
Eudora is an email program for the Windows platform. Eudora contains a vulnerability which may make it possible for an attacker to excecute arbitrary code on a remote system even if 'allow executables in HTML content' is disabled, if the 'Use Microsoft viewer' option is enabled.
The attack can be carried out if the recipient of a maliciously crafted email 'submits' a form in the message.
This may lead to remote attackers gaining access to victim hosts.
** Eudora 5.1.1 is also stated as being vulnerable to this issue. The problem stems from Eudora not treating files with a '.MHTML' extension with caution.
Eudora is an email program for the Windows platform. Eudora contains a vulnerability which may make it possible for an attacker to excecute arbitrary code on a remote system even if 'allow executables in HTML content' is disabled, if the 'Use Microsoft viewer' option is enabled.
The attack can be carried out if the recipient of a maliciously crafted email 'submits' a form in the message.
This may lead to remote attackers gaining access to victim hosts.
** Eudora 5.1.1 is also stated as being vulnerable to this issue. The problem stems from Eudora not treating files with a '.MHTML' extension with caution.
Exploit / POC
Qualcomm Eudora Hidden Attachment Execution Vulnerability
A proof of concept email, containing a form with a 'disguised' submit button as well as two attachments has been created by [email protected]. This email will exploit this vulnerability and execute a program on a victim system.
A proof of concept email, containing a form with a 'disguised' submit button as well as two attachments has been created by [email protected]. This email will exploit this vulnerability and execute a program on a victim system.
Solution / Fix
Qualcomm Eudora Hidden Attachment Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Qualcomm Eudora Hidden Attachment Execution Vulnerability
References:
References:
- Eudora Product Homepage (Qualcomm)