This application requires Javascript for optimal performance.

EasyMail.AddAttachment.ActiveX.Buffer.Overflow

Release Date

Dec 17, 2009

Severity

high

Impact

System Compromise

Description

This indicates an attack attempt against a buffer-overflow vulnerability in the EasyMail ActiveX control in emsmtp.dll.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted argument to the AddAttachment method. It allows a remote attacker to execute arbitrary code.

Affected Products

EasyMail 6 is vulnerable; other versions may also be affected.

Recommended Actions

Currently we are not aware of any officially supplied patch for this issue.

Coverage

IPS
VCM

Reference/s

http://www.securityfocus.com/bid/36440 (BugTraq)

Reference: VID-17998