CVE-2008-1472

UnknownEPSS 39.01%

Last modified

CVE-2008-1472 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.. EPSS estimates a 39.01% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

Metrics

EPSS Probability
39.01%

98.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Computer AssociatesBrightstor Arcserve Backup Laptops Desktops11.5
Computer AssociatesDesktop Management Suiter11.1A
Computer AssociatesDesktop Management Suiter11.2
Computer AssociatesUnicenter Dsm R11 List Control Atx11.2.3.1895
UnicenterAsset Managementr11.1A
UnicenterAsset Managementr11.2
UnicenterDesktop Management Bundler11.1A
UnicenterDesktop Management Bundler11.2
UnicenterRemote Controlr11.1A
UnicenterRemote Controlr11.2
UnicenterSoftware Deliveryr11.1A
UnicenterSoftware Deliveryr11.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-1472?
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.
How severe is CVE-2008-1472?
Severity scoring for CVE-2008-1472 is pending analysis. The EPSS model estimates a 39.01% probability of exploitation in the next 30 days.
How do I fix CVE-2008-1472?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-1472?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST