HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerability
BID:28689
Info
HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerability
| Bugtraq ID: | 28689 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1842 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Mar 20 2009 05:06PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.01 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerability
HP OpenView Network Node Manager is prone to a buffer-overflow vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the Network Node Manager process. This facilitates the remote compromise of affected computers.
Network Node Manager 7.53 running on Microsoft Windows is affected by this issue; other versions and platforms may also be vulnerable.
HP OpenView Network Node Manager is prone to a buffer-overflow vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the Network Node Manager process. This facilitates the remote compromise of affected computers.
Network Node Manager 7.53 running on Microsoft Windows is affected by this issue; other versions and platforms may also be vulnerable.
Exploit / POC
HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerability
References:
References:
- HP OpenView Network Node Manager Product Page (HP)
- [security bulletin] HPSBMA02338 SSRT080024, SSRT080041 rev.1 - HP OpenView Netwo ([email protected] )
- [security bulletin] HPSBMA02338 SSRT080024, SSRT080041 rev.2 - HP OpenView Netwo ([email protected])
- Re: Multiple vulnerabilities in HP OpenView NNM 7.53 (Luigi Auriemma
)