HP Openview Node Manager Vulnerable to Buffer Overrun
By sending a large GET request to the http server included by default in HP Openview Node Manager an attacker can crash the SNMP.EXE service.
September 25, 2000
Reported September 26, 2000 by Delphis Consulting VERSIONS AFFECTED DESCRIPTIONRunning under Windows NT Server 4.0 (SP6), HP Openview Node Manager 6.1 is vulnerable to a buffer overrun that causes the system to stop responding. DEMONSTRATION An attacker has to simply connect to port 80 and send a large GET string that including the EIP is 136 bytes in length. For example (will be wrapped); http://127.0.0.1/OvCgi/OpenView5.exe?Context=SNMP&Action=SNMP&Host=&Oid=AA(x 132 bytes) VENDOR RESPONSE HP had been made aware of the vulnerability and has released a patch available at http://ovweb.external.hp.com/cpe/patches/ CREDITDiscovered by Delphis Consulting |
Read more about:
HPAbout the Author
You May Also Like