Paul Szabo has reported a vulnerability in Eudora, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error within the URL handling functionality. This can be exploited via a malicious email containing a specially crafted overly long link (about 300 bytes).
Successful exploitation allows execution of arbitrary code on a vulnerable system, but requires that the user is tricked into clicking the malicious URL.
The vulnerability has been reported in versions 6.1 and prior for Windows. Other versions may also be affected.
Solution: Qualcomm has released version 6.1.1 which reportedly fixes the URL handling vulnerability:
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to firstname.lastname@example.org