cpe:/a:computer_associates:brightstor_arcserve_backup_laptops_desktops:11.5 cpe:/a:computer_associates:desktop_management_suite:r11.1:a cpe:/a:computer_associates:desktop_management_suite:r11.1:c1 cpe:/a:computer_associates:desktop_management_suite:r11.1:ga cpe:/a:computer_associates:desktop_management_suite:r11.2 cpe:/a:computer_associates:unicenter_dsm_r11_list_control_atx:11.2.3.1895 cpe:/a:unicenter:asset_management:r11.1:a cpe:/a:unicenter:asset_management:r11.1:c1 cpe:/a:unicenter:asset_management:r11.1:ga cpe:/a:unicenter:asset_management:r11.2 cpe:/a:unicenter:asset_management:r11.2:a cpe:/a:unicenter:asset_management:r11.2:c1 cpe:/a:unicenter:desktop_management_bundle:r11.1:a cpe:/a:unicenter:desktop_management_bundle:r11.1:c1 cpe:/a:unicenter:desktop_management_bundle:r11.1:ga cpe:/a:unicenter:desktop_management_bundle:r11.2 cpe:/a:unicenter:desktop_management_bundle:r11.2:a cpe:/a:unicenter:desktop_management_bundle:r11.2:c1 cpe:/a:unicenter:remote_control:r11.1:a cpe:/a:unicenter:remote_control:r11.1:c1 cpe:/a:unicenter:remote_control:r11.1:ga cpe:/a:unicenter:remote_control:r11.2 cpe:/a:unicenter:remote_control:r11.2:a cpe:/a:unicenter:remote_control:r11.2:c1 cpe:/a:unicenter:software_delivery:r11.1:a cpe:/a:unicenter:software_delivery:r11.1:c1 cpe:/a:unicenter:software_delivery:r11.1:ga cpe:/a:unicenter:software_delivery:r11.2 cpe:/a:unicenter:software_delivery:r11.2:a cpe:/a:unicenter:software_delivery:r11.2:c1 CVE-2008-1472 2008-03-24T18:44:00.000-04:00 2017-09-28T21:30:44.240-04:00 9.3 NETWORK MEDIUM NONE COMPLETE COMPLETE COMPLETE http://nvd.nist.gov 2008-03-25T12:32:00.000-04:00 ALLOWS_ADMIN_ACCESS SECTRACK 1019617 BUGTRAQ 20080320 Note about recently publicized CA BrightStor ActiveX exploit code BUGTRAQ 20080328 CA Multiple Products DSM ListCtrl ActiveX Control Buffer Overflow Vulnerability BID 28268 SECUNIA 29408 EXPLOIT-DB 5264 VUPEN ADV-2008-0902 IAVM IAVM:2008-T-0010 XF ca-arcserve-listctrl-bo(41225) CONFIRM http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspx Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.