Qualcomm Eudora Encrypted EMail Attachment/Image Storage Vulnerability
BID:9028
Info
Qualcomm Eudora Encrypted EMail Attachment/Image Storage Vulnerability
| Bugtraq ID: | 9028 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 12 2003 12:00AM |
| Updated: | Nov 12 2003 12:00AM |
| Credit: | This vulnerability was announced in Eudora 6.0.1 release notes. |
| Vulnerable: |
Qualcomm Eudora 6.0 Qualcomm Eudora 5.2.1 Qualcomm Eudora 5.2 .0.9 Qualcomm Eudora 5.2 Qualcomm Eudora 5.1.1 Qualcomm Eudora 5.1 -Jr3 Qualcomm Eudora 5.1 -J Qualcomm Eudora 5.1 Qualcomm Eudora 5.0.2 -Jr2 Qualcomm Eudora 5.0.2 |
| Not Vulnerable: |
Qualcomm Eudora 6.1 |
Discussion
Qualcomm Eudora Encrypted EMail Attachment/Image Storage Vulnerability
Eudora has been reported to be prone to a vulnerability that presents itself during email decryption procedures.
Qualcomm have reported that when an encrypted email is decrypted, images that are embedded in the body of the email and attachments of the email are stored in a decrypted format on the local hard drive. A local attacker who has sufficient access to read the saved images and attachments may potentially reveal confidential data.
Eudora has been reported to be prone to a vulnerability that presents itself during email decryption procedures.
Qualcomm have reported that when an encrypted email is decrypted, images that are embedded in the body of the email and attachments of the email are stored in a decrypted format on the local hard drive. A local attacker who has sufficient access to read the saved images and attachments may potentially reveal confidential data.
Exploit / POC
Qualcomm Eudora Encrypted EMail Attachment/Image Storage Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Qualcomm Eudora Encrypted EMail Attachment/Image Storage Vulnerability
Solution:
The vendor has relased an update to address this issue:
Qualcomm Eudora 6.0
Solution:
The vendor has relased an update to address this issue:
Qualcomm Eudora 6.0
-
Qualcomm Eudora 6.0.1
http://eudora.com/download/
References
Qualcomm Eudora Encrypted EMail Attachment/Image Storage Vulnerability
References:
References:
- EUDORA FOR WINDOWS, VERSION 6.0.1 -- RELEASE NOTES (Qualcomm)
- Eudora Product Homepage (Qualcomm)