HP Openview Node Manager Vulnerable to Buffer Overrun

By sending a large GET request to the http server included by default in HP Openview Node Manager an attacker can crash the SNMP.EXE service.

Steve Manzuik

September 25, 2000

1 Min Read
ITPro Today logo

Reported September 26, 2000 by Delphis Consulting

VERSIONS AFFECTED

DESCRIPTIONRunning under Windows NT Server 4.0 (SP6), HP Openview Node Manager 6.1 is vulnerable to a buffer overrun that causes the system to stop responding.

DEMONSTRATION

An attacker has to simply connect to port 80 and send a large GET string that including the EIP is 136 bytes in length.  For example (will be wrapped);

http://127.0.0.1/OvCgi/OpenView5.exe?Context=SNMP&Action=SNMP&Host=&Oid=AA(x 132 bytes)

VENDOR RESPONSE

HP had been made aware of the vulnerability and has released a patch available at http://ovweb.external.hp.com/cpe/patches/

CREDITDiscovered by Delphis Consulting

Read more about:

HP
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like