Overview
The CA Unicenter DSM ITRM Legends ActiveX control contains an integer overflow vulnerability, which can allow a remote attacker to execute arbitrary code on a vulnerable system.
Description
CA Unicenter DSM ITRM Legends is an ActiveX control that is included with multiple CA products. This ActiveX control, which is provided by gui_cm_ctrls.ocx, contains an integer overflow vulnerability. According to the vendor, the following products are affected: BrightStor ARCServe Backup for Laptops and Desktops r11.5 |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. |
Solution
Apply an update Apply updates, as specified in the CA Security Notice. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Greg Linares of eEye Digital Security for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2008-1786 |
Severity Metric: | 9.48 |
Date Public: | 2008-04-16 |
Date First Published: | 2008-05-08 |
Date Last Updated: | 2008-05-19 19:33 UTC |
Document Revision: | 13 |