Qualcomm Eudora Email Message Deletion Weakness
BID:6688
Info
Qualcomm Eudora Email Message Deletion Weakness
| Bugtraq ID: | 6688 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 25 2003 12:00AM |
| Updated: | Jan 25 2003 12:00AM |
| Credit: | Discovery of this weakness credited to "Blud Clot" <[email protected]>. |
| Vulnerable: |
Qualcomm Eudora 5.2 |
| Not Vulnerable: | |
Discussion
Qualcomm Eudora Email Message Deletion Weakness
A weakness has been reported for Qualcomm Eudora. The weakness exists in the way Eudora deletes email from the "Trash" folder. When a message is deleted from the "Trash" folder, it is only marked as 'deleted' and is still exists in the Trash.mbx file.
The message is only removed from Trash.mbx when the user chooses to compact mailboxes.
A weakness has been reported for Qualcomm Eudora. The weakness exists in the way Eudora deletes email from the "Trash" folder. When a message is deleted from the "Trash" folder, it is only marked as 'deleted' and is still exists in the Trash.mbx file.
The message is only removed from Trash.mbx when the user chooses to compact mailboxes.
Exploit / POC
Qualcomm Eudora Email Message Deletion Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
Qualcomm Eudora Email Message Deletion Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Qualcomm Eudora Email Message Deletion Weakness
References:
References:
- Eudora Product Homepage (Qualcomm)
- Eudora Message Deletion Weakness ("Blud Clot"
)