Qualcomm Eudora Reply-to-all Buffer Overrun Vulnerability
BID:8997
Info
Qualcomm Eudora Reply-to-all Buffer Overrun Vulnerability
| Bugtraq ID: | 8997 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2003 12:00AM |
| Updated: | Nov 10 2003 12:00AM |
| Credit: | Discovery is credited to Hisayuki Shinmachi. |
| Vulnerable: |
Qualcomm Eudora 5.2.1 Qualcomm Eudora 5.2 .0.9 Qualcomm Eudora 5.2 Qualcomm Eudora 5.1.1 Qualcomm Eudora 5.1 -J Qualcomm Eudora 5.1 |
| Not Vulnerable: |
Qualcomm Eudora 6.0 Qualcomm Eudora 5.1 -Jr3 |
Discussion
Qualcomm Eudora Reply-to-all Buffer Overrun Vulnerability
Qualcomm Eudora is prone to a buffer overrun when performing reply-to-all operations with message header fields (such as "From" or "Reply-To") of excessive length. This could be exploited to execute arbitrary code in the context of the client.
This issue was reported to affect Windows versions of the software. It is not known if other platforms are similarly affected.
Qualcomm Eudora is prone to a buffer overrun when performing reply-to-all operations with message header fields (such as "From" or "Reply-To") of excessive length. This could be exploited to execute arbitrary code in the context of the client.
This issue was reported to affect Windows versions of the software. It is not known if other platforms are similarly affected.
Exploit / POC
Qualcomm Eudora Reply-to-all Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Qualcomm Eudora Reply-to-all Buffer Overrun Vulnerability
Solution:
This issue has been addressed in Eudora 6.0 and 5.1-Jr3. Users should contact the vendor to obtain upgrades.
Solution:
This issue has been addressed in Eudora 6.0 and 5.1-Jr3. Users should contact the vendor to obtain upgrades.
References
Qualcomm Eudora Reply-to-all Buffer Overrun Vulnerability
References:
References:
- Eudora Product Homepage (Qualcomm)
- [SNS Advisory No.69] Eudora "Reply-To-All" Buffer Overflow Vulnerability ("Secure Net Service\(SNS\) Security Advisory"
)