PT-2011-3319 · Ca · Ca Output Management Web Viewer
Published
2011-04-27
·
Updated
2021-04-09
·
CVE-2011-1719
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CA Output Management Web Viewer versions 11.0 through 11.5
Description
The issue is related to multiple stack-based buffer overflows in the Web Viewer ActiveX controls. This can be exploited by remote attackers to execute arbitrary code. The exploitation can occur through a long
SRC property value to the PPSViewer ActiveX control in PPSView.ocx before version 1.0.0.7, or a long Title property value to the UOMWV Helper ActiveX control in UOMWV HelperActiveX.ocx before version 11.5.0.1.Recommendations
For CA Output Management Web Viewer versions 11.0 through 11.5, update the
PPSView.ocx to version 1.0.0.7 or later and update the UOMWV HelperActiveX.ocx to version 11.5.0.1 or later. As a temporary workaround, consider restricting access to the PPSViewer and UOMWV Helper ActiveX controls until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Output Management Web Viewer