First published: Fri Dec 31 2004(Updated: )
Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eudora | =3.0 | |
Eudora | =4.0 | |
Eudora | =4.2 | |
Eudora | =4.3 | |
Eudora | =4.3.1 | |
Eudora | =4.3.2 | |
Eudora | =5.0.2 | |
Eudora | =5.0.2j_r2 | |
Eudora | =5.1 | |
Eudora | =5.1.1 | |
Eudora | =5.1j | |
Eudora | =5.1j_r3 | |
Eudora | =5.2 | |
Eudora | =5.2.0.9 | |
Eudora | =5.2.1 | |
Eudora | =6.0 | |
Eudora | =6.0.1 | |
Eudora | =6.0.3 | |
Eudora | =6.0.22 | |
Eudora | =6.1 | |
Eudora | =4.3.1 | |
Eudora | =5.2 | |
Eudora | =6.0 | |
Eudora | =6.0.3 | |
Eudora | =4.3 | |
Eudora | =4.3.2 | |
Eudora | =5.2.1 | |
Eudora | =5.1j | |
Eudora | =5.1j_r3 | |
Eudora | =5.2.0.9 | |
Eudora | =3.0 | |
Eudora | =5.0.2 | |
Eudora | =4.2 | |
Eudora | =5.0.2j_r2 | |
Eudora | =4.0 | |
Eudora | =6.1 | |
Eudora | =5.1 | |
Eudora | =5.1.1 | |
Eudora | =6.0.22 | |
Eudora | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2301 is classified as a denial of service vulnerability.
To fix CVE-2004-2301, upgrade Eudora to version 6.1.1 or later.
CVE-2004-2301 affects Eudora versions 4.3.1, 5.2, 6.0, 6.0.3, and earlier.
The impact of CVE-2004-2301 is that it may cause a crash in the Eudora email client when processing specifically crafted emails.
There are no specific workarounds for CVE-2004-2301; the recommendation is to upgrade to a fixed version.