Oracle.Document.Capture.EasyMail

NameOracle.Document.Capture.EasyMail.ActiveX.Control.Access
Release DateDec 29, 2009
SeverityHigh
ImpactSystem Compromise
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in Oracle Document Capture which is integrated with Oracle Imaging and Process Management and Oracle Universal Content Management products.

The vulnerability is caused by an error when the EasyMail IMAP4 ActiveX component handles a specially crafted LicenseKey property. It allows a remote attacker to execute arbitrary code.
Affected ProductsOracle Document Capture 10.1.3.5.0
Recommended ActionsSet the kill bit for the CLSID {0CEA3FB1-7F88-4803-AA8E-AD021566955D}.
Reference/shttp://secunia.com/advisories/37269/
Reference: VID-17988