PT-2011-3319 · Ca · Ca Output Management Web Viewer

Published

2011-04-27

·

Updated

2021-04-09

·

CVE-2011-1719

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CA Output Management Web Viewer versions 11.0 through 11.5
Description The issue is related to multiple stack-based buffer overflows in the Web Viewer ActiveX controls. This can be exploited by remote attackers to execute arbitrary code. The exploitation can occur through a long SRC property value to the PPSViewer ActiveX control in PPSView.ocx before version 1.0.0.7, or a long Title property value to the UOMWV Helper ActiveX control in UOMWV HelperActiveX.ocx before version 11.5.0.1.
Recommendations For CA Output Management Web Viewer versions 11.0 through 11.5, update the PPSView.ocx to version 1.0.0.7 or later and update the UOMWV HelperActiveX.ocx to version 11.5.0.1 or later. As a temporary workaround, consider restricting access to the PPSViewer and UOMWV Helper ActiveX controls until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1719

Affected Products

Ca Output Management Web Viewer