|
|
| |
The vulnerability is caused due to an integer overflow in ovalarmsrv.exe and can be exploited to cause a heap-based buffer overflow via specially crafted commands sent to port 2954/TCP.
Successful exploitation may allow execution of arbitrary code. |
| |
Credit:
The information has been provided by Dyon Balding.
The original article can be found at: http://secunia.com/secunia_research/2008-38/
|
| |
Vulnerable Systems:
* HP Network Node Manager version 7.53
Patch Availability:
HP-UX (IA): PHSS_39246 or subsequent
HP-UX (PA): PHSS_39245 or subsequent
Linux RedHatAS2.1: LXOV_00093 or subsequent
Linux RedHat4AS-x86_64: LXOV_00094 or subsequent
Solaris: PSOV_03519 or subsequent
Windows: NNM_01197 or subsequent
CVE Information:
CVE-2008-2438
Disclosure Timeline:
08/09/2008 - Vendor notified.
08/09/2008 - Vendor response.
09/10/2008 - Status update requested.
17/10/2008 - Vendor provides status update.
31/03/2009 - Status update requested.
07/04/2009 - Vendor provides status update.
20/04/2009 - Vendor provides status update.
28/04/2009 - Public disclosure.
|
|
|