First published: Sun Apr 22 2012(Updated: )
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.1.1 | |
IBM Rational ClearQuest | =7.1.1.1 | |
IBM Rational ClearQuest | =7.1.1.2 | |
IBM Rational ClearQuest | =7.1.1.3 | |
IBM Rational ClearQuest | =7.1.1.4 | |
IBM Rational ClearQuest | =7.1.2 | |
IBM Rational ClearQuest | =7.1.2.1 | |
IBM Rational ClearQuest | =7.1.2.2 | |
IBM Rational ClearQuest | =7.1.2.3 | |
IBM Rational ClearQuest | =7.1.2.4 | |
IBM Rational ClearQuest | =7.1.2.5 | |
IBM Rational ClearQuest | =7.1.2.6 | |
IBM Rational ClearQuest | =8.0.0 | |
IBM Rational ClearQuest | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0708 has been assigned a medium severity level as it allows remote code execution through a vulnerable ActiveX control.
To fix CVE-2012-0708, update IBM Rational ClearQuest to versions 7.1.1.9, 7.1.2.6, or 8.0.0.2 or later.
CVE-2012-0708 affects IBM Rational ClearQuest versions prior to 7.1.1.9, 7.1.2.6, and 8.0.0.2.
CVE-2012-0708 involves a heap-based buffer overflow in the Ole API of the cqole.dll ActiveX control.
Yes, CVE-2012-0708 can be exploited remotely by attackers through a specially crafted web page.