IBM Rational ClearQuest 'cqole.dll' ActiveX Control Heap Buffer Overflow Vulnerability UPDATED
14 Jul. 2012
Summary
IBM Rational ClearQuest is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Vulnerable Systems:
* IBM IBM Rational ClearQuest 7.1.1 and prior
An attacker can exploit this issue to execute arbitrary code in the context of the application, typically Internet Explorer, that uses the affected ActiveX control. Failed attacks will likely cause denial-of-service conditions.