HP.Application.Recovery.Manager.MSG

NameHP.Application.Recovery.Manager.MSG.PROTOCOL.Stack.Overflow
Last Updated DateJun 01, 2010
Release DateJan 12, 2010
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a stack overflow vulnerability in
HP Application Recovery Manager.

The vulnerability is caused by an error when the vulnerable software handles a malicious packet. It allows a remote attacker to execute arbitrary code.
Affected ProductsHP OpenView Data Protector Application Recovery Manager 5.5
HP OpenView Data Protector Application Recovery Manager 6.0
Recommended ActionsApply the latest update from the vendor:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01943909
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-2280
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3844
Reference/shttp://www.securityfocus.com/bid/37250 (BugTraq)
http://www.securityfocus.com/bid/37396 (BugTraq)
http://www.exploit-db.com/exploits/10715
http://www.zerodayinitiative.com/advisories/ZDI-09-091/
Reference: VID-18028