Hewlett-Packard OpenView OVTrace Multiple Remote Buffer Overflow Vulnerabilities
BID:25255
Info
Hewlett-Packard OpenView OVTrace Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 25255 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3872 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2007 12:00AM |
| Updated: | Nov 26 2009 05:25PM |
| Credit: | Cody Pierce of TippingPoint DV Labs and an anonymous researcher are credited with the discovery of these issues. |
| Vulnerable: |
HP Service Desk Process Insight 2.10 HP Service Desk Process Insight 2.0 HP Service Desk Process Insight 1.10 HP Service Desk Process Insight 1.0 HP OpenView Service Desk Process Insight 2.10 HP OpenView Service Desk Process Insight 2.0 HP OpenView Service Desk Process Insight 1.1 HP OpenView Service Desk Process Insight 1.0 HP Openview Reporter 3.7 HP Openview Quality Manager 1.40 HP Openview Quality Manager 1.3 HP Openview Quality Manager 1.2 SP1 HP OpenView Performance manager 6.0 HP OpenView Performance manager 5.0 HP OpenView Performance Insight 5.1.2 HP OpenView Performance Insight 5.1.1 HP OpenView Performance Insight 5.2 HP OpenView Performance Insight 5.1 HP OpenView Performance Insight 5.0 HP OpenView Performance Agent 4.6 HP OpenView Performance Agent 4.5 HP Openview Operations Manager for Windows 7.5 HP OpenView Operations 8.1 HP OpenView Operations 8.0 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.01 HP OpenView Network Node Manager 6.41 HP Openview Internet Services 6.20 HP Openview Internet Services 6.11 (Japanese) HP Openview Internet Services 6.10 HP Openview Internet Services 6.00 HP OpenView Dashboard 2.01 HP OpenView Business Process Insight 2.10 HP OpenView Business Process Insight 2.0 HP OpenView Business Process Insight 1.1 HP OpenView Business Process Insight 1.0 HP Business Process Insight 2.10 HP Business Process Insight 2.0 HP Business Process Insight 1.1 HP Business Process Insight 1.0 |
| Not Vulnerable: | |
Discussion
Hewlett-Packard OpenView OVTrace Multiple Remote Buffer Overflow Vulnerabilities
HP OpenView applications are prone to multiple remote stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on input that is supplied to opcode handlers of affected services.
These vulnerabilities affect the 'ovtrcsvc.exe' and the 'OVTrace.exe' service.
Attackers can exploit these issues to execute arbitrary code with superuser privileges.
HP OpenView applications are prone to multiple remote stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on input that is supplied to opcode handlers of affected services.
These vulnerabilities affect the 'ovtrcsvc.exe' and the 'OVTrace.exe' service.
Attackers can exploit these issues to execute arbitrary code with superuser privileges.
Exploit / POC
Hewlett-Packard OpenView OVTrace Multiple Remote Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit Framework exploit module is available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit Framework exploit module is available.
Solution / Fix
Hewlett-Packard OpenView OVTrace Multiple Remote Buffer Overflow Vulnerabilities
Solution:
The vendor has released advisories and updates to address these issues. Please see the references for more information.
Solution:
The vendor has released advisories and updates to address these issues. Please see the references for more information.
References
Hewlett-Packard OpenView OVTrace Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- OpenView Homepage (HP)
- HPSBMA02241 SSRT061260 rev.1 - HP OpenView Service Quality Manager (OV SQM) Run (HP)
- [security bulletin] HPSBMA02236 SSRT061260 rev.2 - HP OpenView Performance Manag (HP)
- [security bulletin] HPSBMA02237 SSRT061260 rev.2 - HP OpenView Performance Agent (HP)
- [security bulletin] HPSBMA02238 SSRT061260 rev.2 - HP OpenView Reporter Running (HP)
- [security bulletin] HPSBMA02242 SSRT061260 rev.3 - HP OpenView Network Node Mana ([email protected])
- HPSBMA02235 SSRT061260 rev.1 - HP OpenView Internet Service (OVIS) Running Share (HP)
- HPSBMA02237 SSRT061260 rev.1 - HP OpenView Performance Agent (OVPA) Running Shar (Hp)
- HPSBMA02238 SSRT061260 rev.1 - HP OpenView Reporter Running Shared Trace Service (HP)
- HPSBMA02239 SSRT061260 rev.1 - HP OpenView Operations (OVO) Agents Running Share (HP)
- HPSBMA02242 SSRT061260 rev.1 - HP OpenView Network Node Manager (OV NNM) Running (HP)
- HPSBMA02242 SSRT061260 rev.2 - HP OpenView Network Node Manager (OV NNM) ([email protected])
- HPSBMA02244 SSRT061260 rev.1 - HP OpenView Business Process Insight and Related (HP)
- HPSBMA02245 SSRT061260 rev.1 - HP OpenView Dashboard Running Shared Trace Servic (HP)
- HPSBMA02246 SSRT061260 rev.1 - HP OpenView Performance Insight (OVPI) Running Sh (HP)
- iDefense Security Advisory 08.09.07: Hewlett-Packard OpenView Operations (iDefense Labs)
- Hewlett-Packard OpenView Operations OVTrace Buffer Overflow Vulnerabilities (iDefense Labs)
- HP OpenView Multiple Product Shared Trace Service Stack Overflow Vulnerabilities (TippingPoint)
- HPSBMA02235 SSRT061260 rev.1 - HP OpenView Internet Service (OVIS) Running Share (HP)
- HPSBMA02236 SSRT061260 rev.1 - HP OpenView Performance Manager (OVPM) Running Sh (HP)
- HPSBMA02237 SSRT061260 rev.1 - HP OpenView Performance Agent (OVPA) Running Shar (HP)
- HPSBMA02238 SSRT061260 rev.1 - HP OpenView Reporter Running Shared Trace Service (HP)
- HPSBMA02239 SSRT061260 rev.1 - HP OpenView Operations (OVO) Agents Running Share (HP)
- HPSBMA02240 SSRT061260 rev.1 - HP OpenView Operations Manager for Windows (OVOW) (HP)
- HPSBMA02241 SSRT061260 rev.1 - HP OpenView Service Quality Manager (OV SQM) Runn (HP)
- HPSBMA02242 SSRT061260 rev.1 - HP OpenView Network Node Manager (OV NNM) Running (HP)
- HPSBMA02244 SSRT061260 rev.1 - HP OpenView Business Process Insight and Related (HP)
- HPSBMA02245 SSRT061260 rev.1 - HP OpenView Dashboard Running Shared Trace Servic (HP)
- HPSBMA02246 SSRT061260 rev.1 - HP OpenView Performance Insight (OVPI) Running Sh (HP)