A remote overflow exists in EasyMail Objects. The EasyMail IMAP component fails to properly bounds check the hostname argument being passed to the connect() method resulting in a stack-based buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code on the users system resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution
Upgrade to version 6.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.