Qualcomm Eudora Client and Path Disclosure Vulnerability

low Nessus Network Monitor Plugin ID 1288

Synopsis

The remote host may give an attacker information useful for future attacks

Description

The remote host is running a version of the Eudora mail client that may disclose path information in email messages under certain condtions. If a message containing an attachement is replied to (by an individual running this version of Eudora), the reply message is sent with an appended string containing the full path of the attached file revealing the directory structure of the client.

Solution

Disable the 'Use Microsoft Viewer' option.

Plugin Details

Severity: Low

ID: 1288

Family: SMTP Clients

Published: 8/20/2004

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:W/RC:X

Vulnerability Information

CPE: cpe:/a:qualcomm:eudora

Reference Information

CVE: CVE-2000-0874

BID: 1653