RULE(RULE ID:330479)

Rule General Information
Release Date: 2020-07-02
Rule Name: Oracle Document Capture Easymail AddAttachement Buffer Overflow Vulnerability (CVE-2009-4663)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in the Quiksoft EasyMail Objects 6 ActiveX control allows remote attackers to execute arbitrary code via a long argument to the AddAttachment method.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, Mac OS, Others
Reference: SecurityFocusBID:36440
http://xforce.iss.net/xforce/xfdb/53325
http://www.milw0rm.com/exploits/9705
http://www.bmgsec.com.au/advisories/easymail-6-activex-exploit.txt
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.quiksoft.com/