Eudora contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a user replies to a message that contained an attachment, which will disclose the full path of the saved attachment on a "Attachment Converted" line in the reply, resulting in a loss of confidentiality. A common example is the use of a Virtual Card File (VCF) attachment.
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s):
Remove "Attachment Converted" lines in all outgoing responses.