Summary
This host is running HP OpenView Network Node Manager and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow attacker to cause a buffer overflow via a specially crafted HTTP request to the 'jovgraph.exe' CGI program.
Impact Level: System/Application
Solution
Apply the patch for OpenView NNM version 7.53,
http://seclists.org/bugtraq/2010/Jun/152
http://support.openview.hp.com/selfsolve/patches
http://marc.info/?l=bugtraq&m=128525454219838&w=2
*****
NOTE : No Patch/Solution available for OpenView NNM version 7.51, upgrade to OpenView NNM version 7.53 and apply the patch.
*****
*****
NOTE : Ignore this warning, if above mentioned patch is already applied.
*****
Insight
The flaws are due to boundary errors,
- when creating an error message within 'ovwebsnmpsrv.exe' - within 'getProxiedStorageAddress()' in 'ovutil.dll' - when parsing command line argument variables within 'ovwebsnmpsrv.ex' And an unspecified vulnerability allows remote attackers to cause a denial of service via unknown vectors.
Affected
HP OpenView Network Node Manager version 7.51 and 7.53
References
Severity
Classification
-
CVE CVE-2010-1960, CVE-2010-1961, CVE-2010-1964, CVE-2010-3285 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities