HIGH · 9.3

CVE-2008-1472

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, an...

Vulnerability Description

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Computer AssociatesBrightstor Arcserve Backup Laptops Desktops11.5
Computer AssociatesDesktop Management Suiter11.1
Computer AssociatesUnicenter Dsm R11 List Control Atx11.2.3.1895
UnicenterAsset Managementr11.1
UnicenterDesktop Management Bundler11.1
UnicenterRemote Controlr11.1
UnicenterSoftware Deliveryr11.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-1472?

CVE-2008-1472 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, an...

How severe is CVE-2008-1472?

CVE-2008-1472 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1472?

Check the references section above for vendor advisories and patch information. Affected products include: Computer Associates Brightstor Arcserve Backup Laptops Desktops, Computer Associates Desktop Management Suite, Computer Associates Unicenter Dsm R11 List Control Atx, Unicenter Asset Management, Unicenter Desktop Management Bundle.