HP OpenView Storage Data Protector 'omniinet.exe' Remote Buffer Overflow Vulnerability
BID:48488
Info
HP OpenView Storage Data Protector 'omniinet.exe' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 48488 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-1866 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2011 12:00AM |
| Updated: | Jul 01 2011 08:10PM |
| Credit: | Nahuel C. Riva of Core Security Technologies. |
| Vulnerable: |
HP OpenView Storage Data Protector 6.20 HP OpenView Storage Data Protector 6.11 HP OpenView Storage Data Protector 6.10 HP OpenView Storage Data Protector 6.0 |
| Not Vulnerable: | |
Discussion
HP OpenView Storage Data Protector 'omniinet.exe' Remote Buffer Overflow Vulnerability
HP OpenView Storage Data Protector is prone to a stack-based buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue by sending specially crafted packets to TCP port 5555.
Successful exploits will allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
HP OpenView Storage Data Protector versions 6.0, 6.10, 6.11 and 6.20 are vulnerable.
HP OpenView Storage Data Protector is prone to a stack-based buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue by sending specially crafted packets to TCP port 5555.
Successful exploits will allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
HP OpenView Storage Data Protector versions 6.0, 6.10, 6.11 and 6.20 are vulnerable.
Exploit / POC
HP OpenView Storage Data Protector 'omniinet.exe' Remote Buffer Overflow Vulnerability
The following proof of concept code is available:
The following proof of concept code is available:
Solution / Fix
HP OpenView Storage Data Protector 'omniinet.exe' Remote Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
HP OpenView Storage Data Protector 'omniinet.exe' Remote Buffer Overflow Vulnerability
References:
References: