On TechRepublic: 12 tech terms that make you sound old
BNET Business Network:
BNET
TechRepublic
ZDNet

March 17th, 2008

ActiveX woes bite CA BrightStor

Posted by Larry Dignan @ 6:33 pm

Categories: Exploit code, Hackers, Vulnerability research

Tags: Vulnerability, Computer Associates International Inc., ActiveX, CA BrightStor, Exploitation, ActiveX/COM/COM+/DCOM, Storage Management, It Management, Security, Software Development

Another day another ActiveX problem. This time an ActiveX vulnerability in CA BrightStor ARCServe Backup could be exploited to compromise a user’s system.

A Secunia alert rates the vulnerability “highly critical.” Here are the details:

Krystian Kloskowski has reported a vulnerability in CA BrightStor ARCserve Backup, which can be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to a boundary error in the “AddColumn()” method within the “ListCtrl” ActiveX control (ListCtrl.ocx), which can be exploited to cause a stack-based buffer overflow via an overly long argument passed to the affected method.

Successful exploitation allows execution of arbitrary code e.g. when a user visits a malicious web page.

The vulnerability affects version r11.5, but other versions may be affected. More gory details–and a lot of code–are available in the original advisory from Kloskowski. The flaw is unpatched. And the solution is familiar: Set the kill-bit for the affected ActiveX control.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

Talkback

Add your opinion

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here