POP3: Qualcomm Eudora URL Handling Buffer Overflow

This signature detects attempts to exploit a known vulnerability in Qualcomm Eudora. A successful attack can lead to a stack overflow and arbitrary remote code execution within the context of the affected application.

Extended Description

The WebBrowser control is used in some email clients in order to launch Internet Explorer to render HTML content. A vulnerability exists that may allow an email message to automatically execute message attachments in email clients using the WebBrowser control. If a Windows Media Player file is referenced within a tag, JavaScript commands included in the file may automatically execute when the email is viewed.

Affected Products

Microsoft outlook_98

References

BugTraq: 10298 4343

CVE: CVE-2002-1770

Short Name
POP3:OVERFLOW:EUDORA-URL-BOF
Severity
Major
Recommended
False
Recommended Action
None
Category
POP3
Keywords
Buffer CVE-2002-1770 Eudora Handling Overflow Qualcomm URL bid:10298 bid:4343
Release Date
11/21/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Qualcomm

Microsoft

CVSS Score

5.0

Found a potential security threat?