|
Family: Windows --> Category: infos
EasyMail Object Connect Method Buffer Overflow Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks version of EasyMail Objects
Detailed Explanation for this Vulnerability Test
Synopsis :
A COM object on the remote Windows host is affected by a buffer
overflow vulnerability.
Description :
EasyMail Objects, a set of COM objects for supporting email protocols,
is installed on the remote Windows host.
The IMAP4 component of the version of the DjVu Browser Plug-in
installed on the remote host reportedly is affected by a stack buffer
overflow in the 'Connect' method that can be triggered with a 500+
character hostname. A possible hacker may be able to leverage this issue to
execute arbitrary code on the remote host subject to the user's
rights.
See also :
http://www.security-assessment.com/files/advisories/easymail_advisory.pdf
http://www.securityfocus.com/archive/1/460237/30/0/threaded
Solution :
Upgrade to EasyMail Objects 6.5 or later as that is rumoured to fix
the issue.
Threat Level:
High / CVSS Base Score : 8.0
(AV:R/AC:H/Au:NR/C:C/I:C/A:C/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|