Skip to main content

CA Products DSM "gui_cm_ctrls" ActiveX Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 18 Apr 2008 4499 Views

RISK: Medium Risk

A vulnerability has been identified in various CA products, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by input validation errors in the DSM "gui_cm_ctrls" ActiveX control when handling user-supplied arguments, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • CA BrightStor ARCServe Backup for Laptops and Desktops r11.5
  • CA Desktop Management Suite r11.2 C2
  • CA Desktop Management Suite r11.2 C1
  • CA Desktop Management Suite r11.2a
  • CA Desktop Management Suite r11.2
  • CA Desktop Management Suite r11.1 (GA, a, C1)
  • CA Unicenter Desktop Management Bundle r11.2 C2
  • CA Unicenter Desktop Management Bundle r11.2 C1
  • CA Unicenter Desktop Management Bundle r11.2a
  • CA Unicenter Desktop Management Bundle r11.2
  • CA Unicenter Desktop Management Bundle r11.1 (GA, a, C1)
  • CA Unicenter Asset Management r11.2 C2
  • CA Unicenter Asset Management r11.2 C1
  • CA Unicenter Asset Management r11.2a
  • CA Unicenter Asset Management r11.2
  • CA Unicenter Asset Management r11.1 (GA, a, C1)
  • CA Unicenter Software Delivery r11.2 C2
  • CA Unicenter Software Delivery r11.2 C1
  • CA Unicenter Software Delivery r11.2a
  • CA Unicenter Software Delivery r11.2
  • CA Unicenter Software Delivery r11.1 (GA, a, C1)
  • CA Unicenter Remote Control r11.2 C2
  • CA Unicenter Remote Control r11.2 C1
  • CA Unicenter Remote Control r11.2a
  • CA Unicenter Remote Control r11.2
  • CA Unicenter Remote Control r11.1 (GA, a, C1)
  • CA Desktop and Server Management r11.2 C2
  • CA Desktop and Server Management r11.2 C1
  • CA Desktop and Server Management r11.2a
  • CA Desktop and Server Management r11.2
  • CA Desktop and Server Management r11.1 (GA, a, C1)OpenOffice.org versions prior to 2.4

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link