CVE-2008-1842

Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:openview_network_node_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:4.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:5.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.4:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.10:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.20:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.31:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.41:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:8.01:*:*:*:*:*:*:*

History

21 Nov 2024, 00:45

Type Values Removed Values Added
References () http://aluigi.altervista.org/adv/closedview-adv.txt - () http://aluigi.altervista.org/adv/closedview-adv.txt -
References () http://aluigi.org/poc/closedview.zip - Exploit () http://aluigi.org/poc/closedview.zip - Exploit
References () http://marc.info/?l=bugtraq&m=121321155405849&w=2 - () http://marc.info/?l=bugtraq&m=121321155405849&w=2 -
References () http://secunia.com/advisories/29713 - Vendor Advisory () http://secunia.com/advisories/29713 - Vendor Advisory
References () http://securitytracker.com/id?1019821 - () http://securitytracker.com/id?1019821 -
References () http://www.securityfocus.com/archive/1/493781/100/0/threaded - () http://www.securityfocus.com/archive/1/493781/100/0/threaded -
References () http://www.securityfocus.com/bid/28689 - () http://www.securityfocus.com/bid/28689 -
References () http://www.vupen.com/english/advisories/2008/1159 - Vendor Advisory () http://www.vupen.com/english/advisories/2008/1159 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/41737 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/41737 -

Information

Published : 2008-04-16 17:05

Updated : 2024-11-21 00:45


NVD link : CVE-2008-1842

Mitre link : CVE-2008-1842

CVE.ORG link : CVE-2008-1842


JSON object : View

Products Affected

hp

  • openview_network_node_manager
CWE
CWE-189

Numeric Errors