Lucene search

K
saintSAINT CorporationSAINT:70B7974F5BC370EAE651C89D96AF63C2
HistoryApr 14, 2008 - 12:00 a.m.

HP Openview Network Node Manager ovwparser.dll buffer overflow

2008-04-1400:00:00
SAINT Corporation
download.saintcorporation.com
14

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.95

Percentile

99.4%

Added: 04/14/2008
CVE: CVE-2008-1697
BID: 28569
OSVDB: 43992

Background

HP OpenView Network Node Manager is network availability and performance management software.

Problem

A vulnerability in **ovwparser.dll** allows remote attackers to execute arbitrary commands by sending a request for a long, specially crafted URI which is processed by **ovas.exe**.

Resolution

Apply a fix when available.

References

<http://secunia.com/advisories/29641/&gt;

Limitations

Exploit works on HP OpenView Network Node Manager 7.51.

Platforms

Windows

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.95

Percentile

99.4%