CVE-2012-0708
IBM Rational ClearQuest CQOle ActiveX Control Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
Desbordamiento de búfer en memoria dinámica en el API Ole en el control ActiveX CQOleen cqole.dll en IBM Rational ClearQuest v7.1.1 antes de v7.1.1.9, v7.1.2 antes de v7.1.2.6, y v8.0.0 antes de v8.0.0.2, permite a atacantes remotos ejecutar código de su elección a través de una página modificada que aprovecha un desajuste de la función-prototipo RegisterSchemaRepoFromFileByDbSet.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Rational ClearQuest. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the CQOle ActiveX control. A function prototype mismatch in an ActiveX wrapper results in an extra argument to be pushed onto the stack, thereby misaligning the stack offset. When the function returns, it can be made to jump to a memory address provided via the ActiveX method call. This can be leveraged to execute arbitrary code under the context of the user running the browser.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-01-17 CVE Reserved
- 2012-04-22 CVE Published
- 2012-07-05 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/81443 | Vdb Entry | |
http://secunia.com/advisories/48933 | Third Party Advisory | |
http://www.securityfocus.com/bid/53170 | Vdb Entry | |
http://www.securitytracker.com/id?1026958 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/73492 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/19576 | 2012-07-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ibm.com/support/docview.wss?uid=swg21591705 | 2017-12-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.1 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.1.1 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.1.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.1.2 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.1.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.1.3 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.1.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.1.4 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.1.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2.1 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2.2 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2.3 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2.4 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2.5 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 7.1.2.6 Search vendor "Ibm" for product "Rational Clearquest" and version "7.1.2.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 8.0.0 Search vendor "Ibm" for product "Rational Clearquest" and version "8.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Clearquest Search vendor "Ibm" for product "Rational Clearquest" | 8.0.0.1 Search vendor "Ibm" for product "Rational Clearquest" and version "8.0.0.1" | - |
Affected
|