|
Eudora Email Security Advisory
January 25, 2005
This problem does not affect Macintosh Eudora.
Additionally, the security vulnerabilities mentioned in the September 26, 2003 advisory (below) have been addressed in recent updates to Windows Eudora. The current version of Eudora (6.2.1 as of this writing) is not vulnerable to any of the potential security exploits listed below.
September 26, 2003 Multiple Vulnerabilities
Secunia Advisory SA9729 specifically references two issues.
First issue:
Second issue:
It is always recommended that users should not blindly open attachments from people they do not know. By default, Eudora warns the user when launching a potentially harmful attachment from within a message and will also warn the user if the attachment is launched from within Windows Explorer.
September 25, 2000 Word 2000 Users of Word 2000
should install Eudora 5.0.1 as soon as it becomes available. In the meantime,
users of Word 2000 should launch that program outside of Eudora first
when they have a Word attachment in Eudora they'd like to launch. This
will load the proper .dll files for the Word 2000 application.
August 2000 Mac Password
This bug only affects Eudora 4.3.2 for the Macintosh.
April 2000 File Extensions Cyber attackers continue
to look for creative ways of using email to execute malicious attacks.
One possible method that recently has been described is to attach an executable
(".exe") file and link to that file from the body of an email message
through another attached file by using the Windows shortcut file type
(".lnk"). The LOVELETTERFORYOU virus that uses the “.vbs” file extension
is another. These forms of attack can work in any Windows email client
that allows users to launch files from within an email message.
By default, Windows
Eudora 4.2 and above already warn you when you seek to launch a wide array
of attachments. The following instructions can be used in Eudora 4.2.1
and above to change Eudora's settings to also warn for .lnk and .vbs files:
For versions
of Eudora earlier than 4.2.1, follow these instructions: Close Eudora,
then open the "Eudora.ini" file in your Eudora program folder with a text
editor, such as Notepad. Find the line that has the text "[Settings]"
on it, and add the following line right after that one: Make sure you use
the above text exactly, including the vertical bar that follows "vbs".
You also can use this
syntax with either method above to designate other file extensions you’d
like to be warned about. Simply add the extension and end with a vertical
bar.
If you are using a
version of Eudora earlier than 4.2.1, we recommend you upgrade
to Eudora 5.0. The full application is available for free when used
in Sponsored mode.
March 1999 JavaScripts What can you do to
be safe? We recommend Eudora users do one of two things:
|
|
|
|
| Home | Online Support | Open Source Development | User Forums | Contact Webmaster | | QUALCOMM | Section 508 | Privacy Statement | Terms of Use | |
||
© 1999-2009 QUALCOMM Incorporated. All rights reserved. QUALCOMM and Eudora are registered trademarks of QUALCOMM Incorporated. All other trademarks are the property of their respective owners. |
||