Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Oracle Document Capture EasyMail IMAP4 LicenseKey Buffer Overflow

Subscribe

Check Point Reference: CPAI-2009-305
Date Published:
Severity:
Source: Secunia Advisory: SA37269
Industry Reference(s): N/A
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Oracle Document Capture 10.1.3.5.0
QuikSoft Corp EasyMail prior to 6.5
Vulnerability Description
A buffer overflow vulnerability exists in Oracle Document Capture which is integrated with Oracle Imaging and Process Management and Oracle Universal Content Management products. The vulnerability is due to a boundary error while parsing the LicenseKey property within the EasyMail IMAP4 ActiveX component of the affected product. Remote unauthenticated attackers can exploit this vulnerability by enticing targeted users to open a specially crafted HTML document. Successful exploitation of this vulnerability would allow for arbitrary code execution.
Vulnerability Details
The vulnerability exists in the ActiveX control emimap4.dll. Specifically, the length of the value assigned to the LicenseKey attribute is not validated before being copied into a stack-based buffer of fixed size. Successful exploitation would allow for remote code execution.

Protection Overview

By enabling this protection, IPS-1 will detect and block attempts to access proscribed ActiveX controls via HTTP.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?

1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles, and select the ActiveX Parser protection group.
3. Click User defined bad ActiveX Class ID (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?

Upon attack, the following entries will be logged:

Alert Name: Badfiles ActiveX class in HTML file Alert/Filter
Description: User defined bad ActiveX Class ID