PT-2002-3025 · Qualcomm+1 · Eudora+1
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2313
CVSS v2.0
8.8
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
Eudora email client version 5.1.1
Description:
The issue allows remote attackers to execute arbitrary programs via an HTML email message. This is achieved by using a META refresh tag that references an embedded .mhtml file with ActiveX controls. The ActiveX controls execute a second embedded program, which is then processed by Internet Explorer.
Recommendations:
For Eudora email client version 5.1.1, consider disabling the "use Microsoft viewer" option to mitigate the risk of exploitation. As a temporary workaround, avoid using the Eudora email client to open HTML email messages from untrusted sources until a fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Eudora
Internet Explorer