HP.OpenView.Network.Node.Manager

NameHP.OpenView.Network.Node.Manager.Ovalarmsrv.Integer.Overflow
Release DateJun 23, 2009
SeverityCritical
ImpactSystem compromise
DescriptionThis indicates an attack attempt against an integer-overflow vulnerability in HP OpenView Network Node Manager software.

The vulnerability is caused by an error when the ovalarmsrv.exe server handles a specially crafted request. It allows a remote attacker to execute arbitrary code.
Affected ProductsHP OpenView Network Node Manager (OV NNM) version 7.01
HP OpenView Network Node Manager (OV NNM) version 7.51
HP OpenView Network Node Manager (OV NNM) version 7.53
Recommended ActionsApply the patch supplied by the vendor:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01723303
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2438
Reference/shttp://www.securityfocus.com/bid/34738 (BugTraq)
http://www.vupen.com/english/advisories/2009/1187 (FrSIRT)
Reference: VID-17470