HP OpenView Network Node Manager Unspecified Stack Buffer Overflow Vulnerability
BID:37294
Info
HP OpenView Network Node Manager Unspecified Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 37294 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0898 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2009 12:00AM |
| Updated: | May 05 2010 05:12PM |
| Credit: | Takehiro Takahashi of IBM X-Force |
| Vulnerable: |
HP OpenView Network Node Manager 7.50 Windows 2000/XP HP OpenView Network Node Manager 7.50 Solaris HP OpenView Network Node Manager 7.50 Linux HP OpenView Network Node Manager 7.50 HP-UX 11.X HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.01 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager Unspecified Stack Buffer Overflow Vulnerability
HP OpenView Network Node Manager (NNM) is prone to a stack-based buffer-overflow vulnerability.
Very few technical details are currently available. We will update this BID as more information emerges.
Successfully exploiting this issue allows an attacker to execute arbitrary code with SYSTEM-level privileges, completely compromising affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects NNM 7.01, 7.51, and 7.53.
NOTE: This issue was previously covered in BID 37261 (HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities), but has been assigned its own record to better document it.
HP OpenView Network Node Manager (NNM) is prone to a stack-based buffer-overflow vulnerability.
Very few technical details are currently available. We will update this BID as more information emerges.
Successfully exploiting this issue allows an attacker to execute arbitrary code with SYSTEM-level privileges, completely compromising affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects NNM 7.01, 7.51, and 7.53.
NOTE: This issue was previously covered in BID 37261 (HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities), but has been assigned its own record to better document it.
Exploit / POC
HP OpenView Network Node Manager Unspecified Stack Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP OpenView Network Node Manager Unspecified Stack Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for details.
HP OpenView Network Node Manager 7.53
HP OpenView Network Node Manager 7.01
Solution:
Vendor updates are available. Please see the referenced advisory for details.
HP OpenView Network Node Manager 7.53
-
HP LXOV_00093
Linux RedHatAS2.1
http://support.openview.hp.com/selfsolve/patches -
HP LXOV_00094
Linux RedHat4AS-x86_64
http://support.openview.hp.com/selfsolve/patches -
HP NNM_01197
Windows
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_39245
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_39246
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP PSOV_03519
Solaris
http://support.openview.hp.com/selfsolve/patches
HP OpenView Network Node Manager 7.01
-
HP SSRT080125.701_IP12.hotfix.tar.gz
Windows
ftp://ss080125:[email protected]
References
HP OpenView Network Node Manager Unspecified Stack Buffer Overflow Vulnerability
References:
References: