RETIRED: EasyMail Objects 'emimap4.dll' ActiveX Control Remote Buffer Overflow Vulnerability
BID:36435
Info
RETIRED: EasyMail Objects 'emimap4.dll' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 36435 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2009 12:00AM |
| Updated: | Sep 17 2009 03:20PM |
| Credit: | Sebastian Wolfgarten |
| Vulnerable: |
Quiksoft EasyMail Objects 'emmailstore.dll' 6.0.3.0 |
| Not Vulnerable: | |
Discussion
RETIRED: EasyMail Objects 'emimap4.dll' ActiveX Control Remote Buffer Overflow Vulnerability
EasyMail Objects ActiveX control is prone to a remote buffer-overflow vulnerability because the application fails to properly sanitize user-supplied data.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
The issue affects EasyMail Objects 6.0.3.0; other versions may also be vulnerable.
NOTE: The BID is being retired because the issue is described in BID 22583 (EasyMail Objects Connect Method Remote Stack Buffer Overflow Vulnerability).
EasyMail Objects ActiveX control is prone to a remote buffer-overflow vulnerability because the application fails to properly sanitize user-supplied data.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
The issue affects EasyMail Objects 6.0.3.0; other versions may also be vulnerable.
NOTE: The BID is being retired because the issue is described in BID 22583 (EasyMail Objects Connect Method Remote Stack Buffer Overflow Vulnerability).
Exploit / POC
RETIRED: EasyMail Objects 'emimap4.dll' ActiveX Control Remote Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
The following exploit is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
The following exploit is available:
Solution / Fix
RETIRED: EasyMail Objects 'emimap4.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: EasyMail Objects 'emimap4.dll' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- EasyMail Objects Homepage (Quiksoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Security advisory: Quiksoft EasyMail 6.0.3.0 imap connect() ActiveX stack overf (Sebastian Wolfgarten)