First published: Tue Dec 31 2002(Updated: )
Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program, which is processed by Internet Explorer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eudora | =5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2313 is rated as high severity due to its potential to allow remote code execution.
To fix CVE-2002-2313, disable the 'use Microsoft viewer' option in Eudora or upgrade to a later version that does not have this vulnerability.
CVE-2002-2313 specifically affects Eudora email client version 5.1.1.
CVE-2002-2313 exploits a vulnerability in the processing of HTML email messages to execute arbitrary code.
CVE-2002-2313 will not affect your system if you do not use the Eudora email client, as it is specific to that software.