|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Eudora contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a user replies to a message that contained an attachment, which will disclose the full path of the saved attachment on a "Attachment Converted" line in the reply, resulting in a loss of confidentiality. A common example is the use of a Virtual Card File (VCF) attachment.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s):
Remove "Attachment Converted" lines in all outgoing responses.
|
|
Products |
|
Eudora
 |
4.2 |
4.3 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|