This application requires Javascript for optimal performance.

HP.OpenView.Storage.Data.Protector.Stack.Buffer.Overflow

Release Date

Aug 12, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates a possible attack against a Buffer Overflow vulnerability in the HP OpenView Storage Data Protector.

The vulnerability is caused by the application's failure to perform adequate boundary checks on user supplied data. A successful attack may allow the attacker to execute arbitrary code in the context of the application.

Affected Products

HP OpenView Storage Data Protector 6.20
HP OpenView Storage Data Protector 6.11
HP OpenView Storage Data Protector 6.10
HP OpenView Storage Data Protector 6.0

Recommended Actions

Apply patches or fixes, available from the website:
http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%25253Demr_na-c02872182%25257CdocLocale%25253Den&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1865

Reference/s

http://www.exploit-db.com/exploits/17458/
http://www.exploit-db.com/exploits/17468/
http://www.securityfocus.com/bid/48486 (BugTraq)

Reference: VID-27979