First published: Fri Apr 28 2000(Updated: )
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eudora | =4.0 | |
Eudora | =4.3 | |
Eudora | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0342 is generally rated as a medium severity vulnerability due to its ability to bypass security warnings for executable attachments.
To mitigate CVE-2000-0342, users should update to a later version of Eudora that does not support the executable attachment bypass.
CVE-2000-0342 affects executable files such as .exe, .com, and .bat when referenced through a .lnk file.
Users of Eudora versions 4.0, 4.2, and 4.3 are impacted by the CVE-2000-0342 vulnerability.
Yes, CVE-2000-0342 can be exploited remotely by sending specially crafted emails that utilize the stealth attachment method.