Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method.Referenceshttp://securityreason.com/securityalert/4407http://www.securityfocus.com/bid/27267http://secunia.com/advisories/28443https://exchange.xforce.ibmcloud.com/vulnerabilities/39640https://www.exploit-db.com/exploits/4903http://www.vupen.com/english/advisories/2008/0132