EasyMail.AddAttachment.ActiveX.Buffer

NameEasyMail.AddAttachment.ActiveX.Buffer.Overflow
Release DateDec 17, 2009
SeverityHigh
ImpactSystem Compromise
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in the EasyMail ActiveX control in emsmtp.dll.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted argument to the AddAttachment method. It allows a remote attacker to execute arbitrary code.
Affected ProductsEasyMail 6 is vulnerable; other versions may also be affected.
Recommended ActionsCurrently we are not aware of any officially supplied patch for this issue.
Reference/shttp://www.securityfocus.com/bid/36440 (BugTraq)
Reference: VID-17998