This article originally appeared in TidBITS on 1998-08-10 at 12:00 p.m.
The permanent URL for this article is: http://db.tidbits.com/article/5027
Include images: Off

Eudora Pro Security Hole for Windows Only

by Geoff Duncan

Eudora Pro Security Hole for Windows Only -- After last week's CIAC advisory regarding possible security problems in primarily Windows email clients, a different security issue has been revealed in Windows versions of Eudora Pro. Eudora Pro 4.0, 4.01, and 4.1 betas for Windows can utilize Microsoft's HTML viewer when displaying messages, and that viewer can permit automatic execution of items included in the message, such as Java applets. In theory, other Windows applications that use Microsoft's HTML viewer could also be vulnerable. Qualcomm has released an updater to 4.0.2 that makes Eudora Pro ask for permission before executing programs automatically. As a workaround, disable Microsoft's HTML viewer in the Viewing Mail settings panel of Eudora's Options dialog box. Eudora Light is not vulnerable, and Macintosh versions of Eudora have been safe for years because they encapsulate any attached applications so users must specifically choose to execute them. However, the bottom line remains unchanged: don't launch any attachments unless you're sure they're safe. [GD]

<http://db.tidbits.com/article/05018>
<http://eudora.qualcomm.com/security.html>