HP OpenView Network Node Manager CGI Buffer Overflow Vulnerabilities
BID:26741
Info
HP OpenView Network Node Manager CGI Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26741 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6204 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2007 12:00AM |
| Updated: | Jan 29 2008 06:07PM |
| Credit: | Tenable Network Security working with TippingPoint and the Zero Day Initiative are credited with reporting this issue to the vendor. |
| Vulnerable: |
Nortel Networks Multiservice Data Manager 0 Nortel Networks Enterprise NMS 0 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.01 HP OpenView Network Node Manager 6.41 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager CGI Buffer Overflow Vulnerabilities
HP OpenView Network Node Manager is prone to multiple stack-based buffer-overflow vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the Network Node Manager process. This facilitates the remote compromise of affected computers.
Network Node Manager 6.41, 7.01, and 7.51 are affected when running on HP-UX, Solaris, Windows, and Linux platforms.
HP OpenView Network Node Manager is prone to multiple stack-based buffer-overflow vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the Network Node Manager process. This facilitates the remote compromise of affected computers.
Network Node Manager 6.41, 7.01, and 7.51 are affected when running on HP-UX, Solaris, Windows, and Linux platforms.
Exploit / POC
HP OpenView Network Node Manager CGI Buffer Overflow Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
HP OpenView Network Node Manager CGI Buffer Overflow Vulnerabilities
Solution:
The vendor has released fixes to address these issues. Please see the references for more information.
HP OpenView Network Node Manager 7.01
HP OpenView Network Node Manager 6.41
HP OpenView Network Node Manager 7.51
Solution:
The vendor has released fixes to address these issues. Please see the references for more information.
HP OpenView Network Node Manager 7.01
-
HP NNM_01159
Windows
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36773
HP-UX B.11.11HP-UX B.11.00
http://support.openview.hp.com/patches/patch_index.jsp -
HP PSOV_03480
Solaris
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 6.41
-
HP NNM_01167
Windows
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_37141
HP-UX B.11.11HP-UX B.11.00
http://support.openview.hp.com/patches/patch_index.jsp -
HP PSOV_03489
Solaris
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.51
-
HP LXOV_00054
Linux RedHatAS2.1
http://support.openview.hp.com/patches/patch_index.jsp -
HP NNM_01161
Windows
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36901
HP-UX B.11.23 (PA)HP-UX B.11.11HP-UX B.11.00
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36902
HP-UX B.11.23 (IA)
http://support.openview.hp.com/patches/patch_index.jsp -
HP PSOV_03482
Solaris
http://support.openview.hp.com/patches/patch_index.jsp
References
HP OpenView Network Node Manager CGI Buffer Overflow Vulnerabilities
References:
References:
- HP OpenView Network Node Manager Product Page (HP)
- ZDI-07-071 HP OpenView Network Node Manager Multiple CGI Buffer Overflows (Zeroday Initiative)
- [security bulletin] HPSBMA02281 SSRT061261 rev.1 - HP OpenView Network Node Mana ([email protected])
- ZDI-07-071: HP OpenView Network Node Manager Multiple CGI Buffer Overflows ([email protected])
- 2008008587: Nortel Response to HP OpenView Potential Vulnerabilities (Nortel Networks)