EasyMail Objects 'emmailstore.dll ' ActiveX Control Remote Buffer Overflow Vulnerability
BID:32722
Info
EasyMail Objects 'emmailstore.dll ' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 32722 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2008 12:00AM |
| Updated: | Sep 15 2009 10:11PM |
| Credit: | e.wiZz! and shinnai |
| Vulnerable: |
Quiksoft EasyMail Objects 'emmailstore.dll' 6.5.0.3 Quiksoft EasyMail Objects 'emmailstore.dll' 6.0.2.0 |
| Not Vulnerable: | |
Discussion
EasyMail Objects 'emmailstore.dll ' ActiveX Control Remote Buffer Overflow Vulnerability
EasyMail Objects ActiveX control is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
EasyMail Objects ActiveX control is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
EasyMail Objects 'emmailstore.dll ' ActiveX Control Remote Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
The following exploit code and proof of concept are available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
The following exploit code and proof of concept are available:
Solution / Fix
EasyMail Objects 'emmailstore.dll ' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
EasyMail Objects 'emmailstore.dll ' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- EasyMail Objects Homepage (Quiksoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)