A boundary condition condition exists in the General_ServerName property which by passing an overly long string, and then making a call to the InstallBrowserHelperDll() the data is then copied into a fixed length buffer, thereby overwriting the SEH.
Classification
Location:
Remote / Network Access,
Context Dependent
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity,
Loss of Availability
Solution:
Workaround,
Patch / RCS
Exploit:
Exploit Public,
Exploit Commercial
Disclosure:
Vendor Verified,
Uncoordinated Disclosure
Solution
IBM has released a patch to address this issue, please see the references section for more information. Additionally, it is possible to correct the flaw by implementing the following workaround(s): set the killbit for the affected control.