HP OpenView Network Node Manager 'ovlaunch' Buffer Overflow Vulnerability
BID:33668
Info
HP OpenView Network Node Manager 'ovlaunch' Buffer Overflow Vulnerability
| Bugtraq ID: | 33668 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4562 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2009 12:00AM |
| Updated: | Feb 17 2009 10:18PM |
| Credit: | The discoverer of this vulnerability wishes to remain anonymous. |
| Vulnerable: |
HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.01 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager 'ovlaunch' Buffer Overflow Vulnerability
HP OpenView Network Node Manager (NNM)is prone to a buffer-overflow vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the NNM. Failed exploits can result in a denial-of-service condition.
NNM 7.53 running on Microsoft Windows is affected; other versions and platforms may also be vulnerable.
HP OpenView Network Node Manager (NNM)is prone to a buffer-overflow vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the NNM. Failed exploits can result in a denial-of-service condition.
NNM 7.53 running on Microsoft Windows is affected; other versions and platforms may also be vulnerable.
Exploit / POC
HP OpenView Network Node Manager 'ovlaunch' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
HP OpenView Network Node Manager 'ovlaunch' Buffer Overflow Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
HP OpenView Network Node Manager 7.53
HP OpenView Network Node Manager 7.01
Solution:
The vendor has released updates. Please see the references for more information.
HP OpenView Network Node Manager 7.53
-
HP LXOV_00089
Linux RedHatAS2.1
http://support.openview.hp.com/selfsolve/patches -
HP LXOV_00090
Linux RedHat4AS-x86_64
http://support.openview.hp.com/selfsolve/patches -
HP NNM_01195
Windows
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_38782
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_38783
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP PSOV_03517
Solaris
http://support.openview.hp.com/selfsolve/patches
HP OpenView Network Node Manager 7.01
-
HP NNM_01194
Windows
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_38761
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP PSOV_03516
Solaris
http://support.openview.hp.com/selfsolve/patches
References
HP OpenView Network Node Manager 'ovlaunch' Buffer Overflow Vulnerability
References:
References: