Eudora 5.2.1 attachment spoof

From: Paul Szabo (psz_at_maths.usyd.edu.au)
Date: 05/22/03

  • Next message: Mandrake Linux Security Team: "MDKSA-2003:061 - Updated gnupg packages fix validation bug"
    Date: Thu, 22 May 2003 14:54:13 +1000 (EST)
    To: bugtraq@securityfocus.com
    
    

    Qualcomm Eudora 5.2.1 has been released recently. Quoting from
    http://www.eudora.com/download/eudora/windows/5.2.1/RelNotes.txt :

    > Improved guarding against spoofed Attachment Converted: lines.

    Attachments can still be spoofed by including a CR (ctrl-M, x0d, ASCII 13)
    character anywhere within the "Attachment Converted:" string [these get
    converted internally into a NUL (x00) and ignored], e.g.:

    Attachments can still be spoofed by including a CR=x0d character anywhere
    within the "Attachment Converted:" string (these get converted internally
    into a NUL=x00 and ignored), e.g.:

    Attachment<CR> Converted: "c:\winnt\system32\calc.exe" NoAttachIcon
    Attachment Converted: "c:\winnt\system32\calc.exe" NoAttachIcon

    (First line with four-character <CR> marker for the sake of Eudora users.)

    For history, please see also:
      http://www.securityfocus.com/archive/1/299730
      http://www.securityfocus.com/archive/1/286634

    Cheers,

    Paul Szabo - psz@maths.usyd.edu.au http://www.maths.usyd.edu.au:8000/u/psz/
    School of Mathematics and Statistics University of Sydney 2006 Australia


  • Next message: Mandrake Linux Security Team: "MDKSA-2003:061 - Updated gnupg packages fix validation bug"

    Relevant Pages

    • Eudora 5.2.1 attachment spoof
      ... Qualcomm Eudora 5.2.1 has been released recently. ... Attachments can still be spoofed by including a CR=x0d character anywhere ... within the "Attachment Converted:" string (these get converted internally ... "Information Security and the Disappearing Perimeter" ...
      (NT-Bugtraq)
    • [Full-Disclosure] Eudora 5.2.1 attachment spoof
      ... Qualcomm Eudora 5.2.1 has been released recently. ... converted internally into a NUL (x00) and ignored], ... Attachments can still be spoofed by including a CR=x0d character anywhere ... within the "Attachment Converted:" string (these get converted internally ...
      (Full-Disclosure)
    • [TOMOYO #15 3/8] Common functions for TOMOYO Linux.
      ... This file contains common functions (e.g. policy I/O, pattern matching). ... Since TOMOYO Linux is a name based access control, ... TOMOYO Linux's string manipulation functions make reviewers feel crazy, ... the Linux kernel accepts all characters but NUL character ...
      (Linux-Kernel)
    • RfD: Escaped Strings version 4
      ... the S" string can only contain printable characters, ... the S" string cannot contain the '"' character, ... as an escape character for the entry of characters that cannot be ... \b BS (backspace, ASCII 8) ...
      (comp.lang.forth)
    • RfD: Escaped Strings version 4
      ... the S" string can only contain printable characters, ... the S" string cannot contain the '"' character, ... as an escape character for the entry of characters that cannot be ... \b BS (backspace, ASCII 8) ...
      (comp.lang.forth)