CVE-2012-0708: Buffer Overflow
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0708?
CVE-2012-0708 has been assigned a medium severity level as it allows remote code execution through a vulnerable ActiveX control.
How do I fix CVE-2012-0708?
To fix CVE-2012-0708, update IBM Rational ClearQuest to versions 7.1.1.9, 7.1.2.6, or 8.0.0.2 or later.
Who is affected by CVE-2012-0708?
CVE-2012-0708 affects IBM Rational ClearQuest versions prior to 7.1.1.9, 7.1.2.6, and 8.0.0.2.
What components are involved in CVE-2012-0708?
CVE-2012-0708 involves a heap-based buffer overflow in the Ole API of the cqole.dll ActiveX control.
Can CVE-2012-0708 be exploited remotely?
Yes, CVE-2012-0708 can be exploited remotely by attackers through a specially crafted web page.