HP OpenView Network Node Manager HTTP Request Multiple Buffer Overflow Vulnerabilities
BID:33147
Info
HP OpenView Network Node Manager HTTP Request Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 33147 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0067 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2009 12:00AM |
| Updated: | May 05 2010 03:42PM |
| Credit: | JJ Reyes, Secunia Research |
| Vulnerable: |
HP OpenView Network Node Manager 7.0 .1 Windows 2000/XP HP OpenView Network Node Manager 7.0 .1 Solaris HP OpenView Network Node Manager 7.0 .1 HP-UX 11.X HP OpenView Network Node Manager 7.0 .1 HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.01(IA) HP OpenView Network Node Manager 7.01 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager HTTP Request Multiple Buffer Overflow Vulnerabilities
HP OpenView Network Node Manager is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting these issues may allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect HP OpenView Network Node Manager 7.51 with NNM_01168; other versions may also be affected.
HP OpenView Network Node Manager is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting these issues may allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
These issues affect HP OpenView Network Node Manager 7.51 with NNM_01168; other versions may also be affected.
Exploit / POC
HP OpenView Network Node Manager HTTP Request Multiple Buffer Overflow Vulnerabilities
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
HP OpenView Network Node Manager HTTP Request Multiple Buffer Overflow Vulnerabilities
Solution:
Vendor updates are available. Please see the referenced advisories for more information.
HP OpenView Network Node Manager 7.53
HP OpenView Network Node Manager 7.01
Solution:
Vendor updates are available. Please see the referenced advisories for more information.
HP OpenView Network Node Manager 7.53
-
HP LXOV_00093
Linux RedHatAS2.1
http://support.openview.hp.com/selfsolve/patches -
HP LXOV_00094
Linux RedHat4AS-x86_64
http://support.openview.hp.com/selfsolve/patches -
HP NNM_01197
Windows
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_39245
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_39246
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP PSOV_03519
Solaris
http://support.openview.hp.com/selfsolve/patches
HP OpenView Network Node Manager 7.01
-
HP NNM_01194
Windows
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_38761
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP PSOV_03516
Solaris
http://support.openview.hp.com/selfsolve/patches
References
HP OpenView Network Node Manager HTTP Request Multiple Buffer Overflow Vulnerabilities
References:
References:
- HP OpenView Network Node Manager Product Page (HP)
- Secunia Research: HP OpenView Network Node Manager Multiple Vulnerabilities (Secunia)
- HPSBMA02400 SSRT080144 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote ([email protected])
- Secunia Research: HP OpenView Network Node Manager Multiple Vulnerabilities (Secunia Research
)