Re: Microsoft Security Bulletin (MS98-008)

From: David Kozinn (davidat_private)
Date: Wed Jul 29 1998 - 06:48:50 PDT

  • Next message: der Mouse: "Re: Fwd: Any user can panic OpenBSD machine"

    At 09:05 PM 7/28/98 , Brett Glass wrote:
    
    >I then polled the server with Eudora Pro 4.0.1. When the message came in,
    it was garbled and the MIME header with the gigantic file name appeared in
    the body of the message when it should not have done so. The huge file name
    was displayed next to an icon, but clicking on the icon did not bring up
    the attached file; it generated an error message instead. I deleted the
    message, and the attachment was not deleted with it as it should have been.
    >
    >I continued to use the mail client, and shortly thereafter it GP faulted.
    
    Interesting. Qualcomm says that its products are not affected here:
    http://eudora.qualcomm.com/press/
    
    However, the wording there says "... Eudora does not allow any unauthorized
    programs to be automatically executed on a user's system...", which seems
    to me that problem with merely receiving long filenames isn't a problem (as
    it is with the other products), but that a problem doesn't necessarily
    _not_ exist when you try to explicitly run the (bogus) attachment, as
    you've seen.
    --
    David Kozinn                    davidat_private
    Strategic Services             +1-212-708-2080
    Mutual Of New York
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:09:46 PDT