This application requires Javascript for optimal performance.

EMC.ApplicationXtender.Activex.Control.Buffer.Overflow

Release Date

Nov 03, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a memory corruption vulnerability in some EMC's software.

The vulnerability is located in the "keyhelp.ocx" ActiveX control through a
miss-use of the "JumpURL" property. It may allow remote attackers to execute
arbitrary code in the context of the application using the affected ActiveX
control.

Affected Products

EMC Documentum ApplicationXtender Desktop 5.4
EMC Captiva Quickscan Pro 4.6 SP1

Recommended Actions

Disable this ActiveX Control by setting the kill bit. For more information, visit:
http://support.microsoft.com/kb/240797

Coverage

IPS
VCM

Reference/s

http://www.securityfocus.com/bid/36546 (BugTraq)

Reference: VID-17793