EasyMail Objects 'SubmitToExpress()' Method Remote Stack Buffer Overflow Vulnerability
BID:41887
Info
EasyMail Objects 'SubmitToExpress()' Method Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 41887 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2007 12:00AM |
| Updated: | Feb 16 2007 12:00AM |
| Credit: | rgod and Will Dormann of the CERT/CC |
| Vulnerable: |
Quiksoft EasyMail Objects 'emsmtp.dll' 6.0.2.0 Giant Company Spam Inspector 4.0.354 |
| Not Vulnerable: | |
Discussion
EasyMail Objects 'SubmitToExpress()' Method Remote Stack Buffer Overflow Vulnerability
EasyMail Objects is prone to a remote buffer-overflow vulnerability because the it fails to perform adequate boundary checks on user-supplied data before copying it to an insufficiently sized buffer.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
EasyMail Objects 'emsmtp.dll' 6.0.2.0 is vulnerable; other versions may also be affected.
Spam Inspector 4.0.354 is vulnerable.
EasyMail Objects is prone to a remote buffer-overflow vulnerability because the it fails to perform adequate boundary checks on user-supplied data before copying it to an insufficiently sized buffer.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
EasyMail Objects 'emsmtp.dll' 6.0.2.0 is vulnerable; other versions may also be affected.
Spam Inspector 4.0.354 is vulnerable.
Exploit / POC
EasyMail Objects 'SubmitToExpress()' Method Remote Stack Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
References
EasyMail Objects 'SubmitToExpress()' Method Remote Stack Buffer Overflow Vulnerability
References:
References:
- Quiksoft Homepage (Quiksoft)