CVE-2007-2280

Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:openview_storage_data_protector:5.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_storage_data_protector:6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:30

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=126106261622540&w=2 - () http://marc.info/?l=bugtraq&m=126106261622540&w=2 -
References () http://securitytracker.com/id?1023361 - Patch () http://securitytracker.com/id?1023361 - Patch
References () http://www.securityfocus.com/bid/37396 - () http://www.securityfocus.com/bid/37396 -
References () http://www.vupen.com/english/advisories/2009/3594 - () http://www.vupen.com/english/advisories/2009/3594 -
References () http://www.zerodayinitiative.com/advisories/ZDI-09-099/ - Patch () http://www.zerodayinitiative.com/advisories/ZDI-09-099/ - Patch

Information

Published : 2009-12-18 19:30

Updated : 2024-11-21 00:30


NVD link : CVE-2007-2280

Mitre link : CVE-2007-2280

CVE.ORG link : CVE-2007-2280


JSON object : View

Products Affected

hp

  • openview_storage_data_protector
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer