HP.OpenView.Network.Node.Manager.Rping

NameHP.OpenView.Network.Node.Manager.Rping.Stack.Buffer.Overflow
Last Updated DateNov 24, 2009
Release DateAug 25, 2009
SeverityCritical
ImpactSystem compromise
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in HP Network Node Manager.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted HTTP request. It allows a remote attacker to execute arbitrary code.
Affected ProductsHP OpenView Network Node Manager (OV NNM) version 7.51
HP OpenView Network Node Manager (OV NNM) version 7.53
Recommended ActionsApply the patch supplied by the vendor:
http://support.openview.hp.com/selfsolve/patches
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1420
Reference/shttp://www.securityfocus.com/bid/35267 (BugTraq)
http://www.vupen.com/english/advisories/2009/1549 (FrSIRT)
Reference: VID-17636