Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.
Link | Tags |
---|---|
http://marc.info/?l=ntbugtraq&m=110053102601655&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18064 | vdb entry |
http://marc.info/?l=bugtraq&m=110037078519691&w=2 | mailing list |
http://packetstormsecurity.nl/0411-exploits/eudora62014.txt | vendor advisory |