Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as...
Vulnerability Description
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-1472
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/28268
- http://www.vupen.com/english/advisories/2008/0902/references
- http://secunia.com/advisories/29408
- https://www.exploit-db.com/exploits/5264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41225
- http://www.securityfocus.com/archive/1/489893/100/0/threaded
- http://www.securitytracker.com/id?1019617
- http://www.securityfocus.com/archive/1/490263/100/0/threaded
- http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspx
Affected Vendor
computer associates
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.