Vulnerability Description
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Eudora | 4.0 |
Related Weaknesses (CWE)
References
- http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-177Not ApplicableVendor Advisory
- http://www.peacefire.org/security/stealthattach/explanation.htmlExploit
- http://www.securityfocus.com/bid/1157Broken LinkThird Party AdvisoryVDB Entry
- http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-177Not ApplicableVendor Advisory
- http://www.peacefire.org/security/stealthattach/explanation.htmlExploit
- http://www.securityfocus.com/bid/1157Broken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2000-0342?
CVE-2000-0342 is a vulnerability with a CVSS score of 7.5 (HIGH). Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
How severe is CVE-2000-0342?
CVE-2000-0342 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0342?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Eudora.