EasyMail Objects IMAP4 Component Connect Method Remote Overflow

This script is Copyright (C) 2007-2015 Tenable Network Security, Inc.


Synopsis :

A COM object on the remote Windows host is affected by a buffer
overflow vulnerability.

Description :

EasyMail Objects, a set of COM objects for supporting email protocols,
is installed on the remote Windows host.

The IMAP4 component of the version of the DjVu Browser Plug-in
installed on the remote host reportedly is affected by a stack buffer
overflow in the 'Connect' method that can be triggered with a 500+
character hostname. An attacker may be able to leverage this issue to
execute arbitrary code on the remote host subject to the user's
privileges.

See also :

http://www.nessus.org/u?6cbe0b07
http://www.securityfocus.com/archive/1/460237/30/0/threaded

Solution :

Install the latest version of EasyMail Objects 6.5 or later as that is
rumoured to fix the issue.

Risk factor :

High / CVSS Base Score : 7.6
(CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 24355 (easymail_objects_imap_connect_overflow.nasl)

Bugtraq ID: 22583

CVE ID: CVE-2007-1029

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now