S-287: CA Unicenter DSM ITRM Legends ActiveX Vulnerability


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) S-287: CA Unicenter DSM ITRM Legends ActiveX Vulnerability
# 1  
Old 05-09-2008
S-287: CA Unicenter DSM ITRM Legends ActiveX Vulnerability

The CA Unicenter DMS ITRM Legends ActiveX control contains an integer overflow vulnerability, which can allow a remote attacker to execute arbitrary code on a vulnerable system. The risk is MEDIUM. By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
COM_LOAD_TYPELIB(3)							 1						       COM_LOAD_TYPELIB(3)

com_load_typelib - Loads a Typelib

SYNOPSIS
bool com_load_typelib (string $typelib_name, [bool $case_insensitive = true]) DESCRIPTION
Loads a type-library and registers its constants in the engine, as though they were defined using define(3). Note that it is much more efficient to use the "" configuration setting to pre-load and register the constants, although not so flexible. If you have turned on "", then PHP will attempt to automatically register the constants associated with a COM object when you instantiate it. This depends on the interfaces provided by the COM object itself, and may not always be possible. PARAMETERS
o $typelib_name -$typelib_name can be one of the following: o The filename of a .tlb file or the executable module that contains the type library. o The type library GUID, followed by its version number, for example {00000200-0000-0010-8000-00AA006D2EA4},2,0. o The type library name, e.g. Microsoft OLE DB ActiveX Data Objects 1.0 Library. PHP will attempt to resolve the type library in this order, as the process gets more and more expensive as you progress down the list; searching for the type library by name is handled by physically enumerating the registry until we find a match. o $case_insensitive - The $case_insensitive behaves in the same way as the parameter with the same name in the define(3) function. RETURN VALUES
Returns TRUE on success or FALSE on failure. PHP Documentation Group COM_LOAD_TYPELIB(3)