A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Computer Associates products. The specific flaw exists within the processing of an improperly defined “coffFiles” field in .CAB archives. Large values result in an unbounded data copy operation which can result in an exploitable stack-based buffer overflow.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57067/ZDI-07-035.txt
Source: https://packetstormsecurity.com/files/57067/Zero-Day-Initiative-Advisory-07-035.html

