notoriously trustworthy
Showing 1 - 1 of 1 RSS Feed

Files

iDEFENSE Security Advisory 2009-02-06.3
Posted Feb 6, 2009
Authored by iDefense Labs | Site idefense.com

iDefense Security Advisory 02.06.09 - Remote exploitation of a BSS based buffer overflow vulnerability in Hewlett-Packard Development Co. LP (HP)'s Network Node Manager could allow an attacker to execute arbitrary code with the privileges of the affected service. The vulnerability exists within the 'ovlaunch' CGI application, which is used to launch the remote user interface. iDefense has confirmed the existence of this vulnerability in Network Node Manager version 7.53 for Windows. Previous versions may also be affected. The Linux version of 'ovlaunch' contains the vulnerable code, but it is not triggered. The actual hostname is used instead of the attacker supplied 'Host' parameter.

tags | advisory, remote, overflow, arbitrary, cgi
systems | linux, windows
advisories | CVE-2008-4562
MD5 | 7b8e01106925c5d16d8f5fd40d5ab4ce
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close