HP Openview Network Node Manager Alarm Service Buffer Overrun Vulnerability
BID:1317
Info
HP Openview Network Node Manager Alarm Service Buffer Overrun Vulnerability
| Bugtraq ID: | 1317 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 06 2000 12:00AM |
| Updated: | Jun 06 2000 12:00AM |
| Credit: | Discovered by the Delphis Consulting Internet Security Team (DCIST) <[email protected]> and publicized in a Security Team Advisory DST2K0012 on June 6, 2000. |
| Vulnerable: |
HP OpenView Network Node Manager 6.10 |
| Not Vulnerable: | |
Discussion
HP Openview Network Node Manager Alarm Service Buffer Overrun Vulnerability
Quoted from Delphis Security Advisory DST2K0012:
By using the Alarm service which is shipped and installed by default with HP openview network node manager it is possible to cause a Buffer overrun in OVALARMSRV overwriting the EIP allowing the execution of arbitry code. This is done be connecting to post 2345 which the port resides on by default and sending a large string. The string has to be a length of 4064 + EIP (4 bytes) making a total of 4068 bytes.
Quoted from Delphis Security Advisory DST2K0012:
By using the Alarm service which is shipped and installed by default with HP openview network node manager it is possible to cause a Buffer overrun in OVALARMSRV overwriting the EIP allowing the execution of arbitry code. This is done be connecting to post 2345 which the port resides on by default and sending a large string. The string has to be a length of 4064 + EIP (4 bytes) making a total of 4068 bytes.
Solution / Fix
HP Openview Network Node Manager Alarm Service Buffer Overrun Vulnerability
Solution:
HP has provided the following patches which rectify this issue:
HP OpenView Network Node Manager 6.10
Solution:
HP has provided the following patches which rectify this issue:
HP OpenView Network Node Manager 6.10
-
HP NNM_00621
WinNT4.X/2000
http://ovweb.external.hp.com:80/cpe/cgi-bin/saveAs?productName=/home/f tp/pub/cpe/patches/nnm/6.1/intelNT_4.X/NNM_00621.EXE -
HP PHSS_22406
HP-UX 10.X
http://ovweb.external.hp.com:80/cpe/cgi-bin/saveAs?productName=/home/f tp/pub/cpe/patches/nnm/6.1/s700_800_10.X/PHSS_22406 -
HP PHSS_22407
HP-UX 11.00
http://ovweb.external.hp.com:80/cpe/cgi-bin/saveAs?productName=/home/f tp/pub/cpe/patches/nnm/6.1/s700_800_11.X/PHSS_22407 -
HP PSOV_02830
Solaris 2.X
http://ovweb.external.hp.com:80/cpe/cgi-bin/saveAs?productName=/home/f tp/pub/cpe/patches/nnm/6.1/sparc_2.X/PSOV_02830
References
HP Openview Network Node Manager Alarm Service Buffer Overrun Vulnerability
References:
References: