Qualcomm Eudora File Attachment Spoofing Variant Vulnerability
BID:7653
Info
Qualcomm Eudora File Attachment Spoofing Variant Vulnerability
| Bugtraq ID: | 7653 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2003 12:00AM |
| Updated: | May 22 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Paul Szabo <[email protected]>. |
| Vulnerable: |
Qualcomm Eudora 6.0 Qualcomm Eudora 5.2.1 |
| Not Vulnerable: | |
Discussion
Qualcomm Eudora File Attachment Spoofing Variant Vulnerability
Eudora is reported to be prone to an issue which may allow attackers to spoof the file extension in an attachment. This may aid an attacker in enticing a user of the e-mail client into executing malicious content.
It is possible to refer to other files or attachments in a message through specially formatted inline text.
If the CR (carriage return) character (0x0D, Ctrl-M) is embedded anywhere in the 'Attachment Converted' string, it is possible to execute message attachments without further user interaction.
It is likely that this vulnerability is related to the issue described in BID 5432.
Eudora is reported to be prone to an issue which may allow attackers to spoof the file extension in an attachment. This may aid an attacker in enticing a user of the e-mail client into executing malicious content.
It is possible to refer to other files or attachments in a message through specially formatted inline text.
If the CR (carriage return) character (0x0D, Ctrl-M) is embedded anywhere in the 'Attachment Converted' string, it is possible to execute message attachments without further user interaction.
It is likely that this vulnerability is related to the issue described in BID 5432.
Solution / Fix
Qualcomm Eudora File Attachment Spoofing Variant Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.