9.3

CVE-2008-1472

Exploit
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Computer Associates ≫ Desktop Management Suite Version r11.1 Update a
Computer Associates ≫ Desktop Management Suite Version r11.1 Update c1
Computer Associates ≫ Desktop Management Suite Version r11.1 Update ga
Unicenter ≫ Asset Management Version r11.1 Update a
Unicenter ≫ Asset Management Version r11.1 Update c1
Unicenter ≫ Asset Management Version r11.1 Update ga
Unicenter ≫ Asset Management Version r11.2
Unicenter ≫ Asset Management Version r11.2 Update a
Unicenter ≫ Asset Management Version r11.2 Update c1
Unicenter ≫ Desktop Management Bundle Version r11.1 Update a
Unicenter ≫ Desktop Management Bundle Version r11.1 Update c1
Unicenter ≫ Desktop Management Bundle Version r11.1 Update ga
Unicenter ≫ Desktop Management Bundle Version r11.2 Update a
Unicenter ≫ Desktop Management Bundle Version r11.2 Update c1
Unicenter ≫ Remote Control Version r11.1 Update a
Unicenter ≫ Remote Control Version r11.1 Update c1
Unicenter ≫ Remote Control Version r11.1 Update ga
Unicenter ≫ Remote Control Version r11.2
Unicenter ≫ Remote Control Version r11.2 Update a
Unicenter ≫ Remote Control Version r11.2 Update c1
Unicenter ≫ Software Delivery Version r11.1 Update a
Unicenter ≫ Software Delivery Version r11.1 Update c1
Unicenter ≫ Software Delivery Version r11.1 Update ga
Unicenter ≫ Software Delivery Version r11.2
Unicenter ≫ Software Delivery Version r11.2 Update a
Unicenter ≫ Software Delivery Version r11.2 Update c1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 39.01% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspx
http://secunia.com/advisories/29408
Vendor Advisory
http://www.securityfocus.com/archive/1/489893/100/0/threaded
http://www.securityfocus.com/archive/1/490263/100/0/threaded
http://www.securityfocus.com/bid/28268
Exploit
http://www.securitytracker.com/id?1019617
http://www.vupen.com/english/advisories/2008/0902/references
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/41225
https://www.exploit-db.com/exploits/5264