CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX Control Remote Buffer Overflow Vulnerability
BID:37133
Info
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 37133 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2007 12:00AM |
| Updated: | Nov 26 2009 04:05PM |
| Credit: | Unknown |
| Vulnerable: |
Computer Associates eTrust PestPatrol Anti-spyware 0 |
| Not Vulnerable: | |
Discussion
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX Control Remote Buffer Overflow Vulnerability
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX control is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to execute arbitrary code in the context of the application. Successful exploits will compromise the application and the computer. Failed attacks will cause denial-of-service conditions.
This issue affects 'ppctl.dll' 5.6.7.9.
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX control is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can leverage this issue to execute arbitrary code in the context of the application. Successful exploits will compromise the application and the computer. Failed attacks will cause denial-of-service conditions.
This issue affects 'ppctl.dll' 5.6.7.9.
Exploit / POC
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX Control Remote Buffer Overflow Vulnerability
A Metasploit Framework exploit module is available:
A Metasploit Framework exploit module is available:
Solution / Fix
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CA eTrust PestPatrol Anti-Spyware 'ppctl.dl' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- CA.ETrust.PestPatrol.Ppctl.Dll.ActiveX.Access (Fortinet)
- Microsoft Knowledge Base Article 240797 (Microsoft)