HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
BID:34135
Info
HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 34135 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0921 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2009 12:00AM |
| Updated: | May 05 2010 04:12PM |
| Credit: | Oren Isacson of Core Security Technologies |
| Vulnerable: |
HP OpenView Network Node Manager 7.0 .1 Windows 2000/XP HP OpenView Network Node Manager 7.0 .1 Solaris HP OpenView Network Node Manager 7.0 .1 Linux HP OpenView Network Node Manager 7.0 .1 HP-UX 11.X HP OpenView Network Node Manager 7.0 .1 HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Nod Manager 7.53 patch NNM_01195 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
HP OpenView Network Node Manager is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting this issue may allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
HP OpenView Network Node Manager 7.51, 7.53, and 7.53 with patch NNM_01195 are vulnerable.
HP OpenView Network Node Manager is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers.
Successfully exploiting this issue may allow an attacker to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely crash the application.
HP OpenView Network Node Manager 7.51, 7.53, and 7.53 with patch NNM_01195 are vulnerable.
Exploit / POC
HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the [email protected]
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the [email protected]
Solution / Fix
HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisories for more information.
Solution:
Vendor updates are available. Please see the referenced advisories for more information.
References
HP OpenView Network Node Manager 'Accept-Language' HTTP Header Heap Buffer Overflow Vulnerability
References:
References:
- HP OpenView Buffer Overflows (CORE Security Technologies)
- HP OpenView Network Node Manager Product Page (HP)
- [security bulletin] HPSBMA02416 SSRT090008 rev.4 - HP OpenView Network Node Mana ([email protected])
- [security bulletin] HPSBMA02416 SSRT090008 rev.5 - HP OpenView Network Node Mana ([email protected])