Vulnerabilities > CVE-2009-0714 - Privilege Escalation vulnerability in HP Data Protector Express 3.5/4.0
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
OS | 1 | |
OS | 1 | |
OS | 1 | |
Application | 5 |
Exploit-Db
description HP Data Protector 4.00-SP1b43064 Remote Memory Leak/Dos (meta). CVE-2009-0714. Dos exploit for windows platform file exploits/windows/dos/9007.rb id EDB-ID:9007 last seen 2016-02-01 modified 2009-06-23 platform windows port published 2009-06-23 reporter Nibin source https://www.exploit-db.com/download/9007/ title HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Dos meta type dos description HP Data Protector 4.00-SP1b43064 Remote Memory Leak/Dos Exploit. CVE-2009-0714. Dos exploit for windows platform file exploits/windows/dos/9006.py id EDB-ID:9006 last seen 2016-02-01 modified 2009-06-23 platform windows port published 2009-06-23 reporter Nibin source https://www.exploit-db.com/download/9006/ title HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Dos Exploit type dos
Nessus
NASL family | Windows |
NASL id | HP_DATA_PROTECTOR_EXP_PRIV_ESCALATION.NASL |
description | HP Data Protector Express is installed on the remote host. The installed version of the software is affected by an unspecified local privilege escalation vulnerability. A local attacker could exploit this vulnerability to trigger a denial of service condition or execute arbitrary code with system level privileges. According to reports, this flaw could also be triggered remotely by exploiting a memory leak vulnerability, see references for more information. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 38792 |
published | 2009-05-15 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/38792 |
title | HP Data Protector Express Crafted Traffic Remote Memory Disclosure |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/78610/hpdp2-dos.txt |
id | PACKETSTORM:78610 |
last seen | 2016-12-05 |
published | 2009-06-24 |
reporter | Nibin |
source | https://packetstormsecurity.com/files/78610/HP-Data-Protector-4.00-sp1-43064-Denial-Of-Service.html |
title | HP Data Protector 4.00-sp1 43064 Denial Of Service |
Seebug
bulletinFamily exploit description BUGTRAQ ID: 34955 CVE(CAN) ID: CVE-2009-0714 HP Data Protector软件能够实现自动化的高性能备份与恢复,支持通过磁盘和磁带进行备份和恢复。 HP Data Protector使用私有协议与远程客户端通讯。如果远程客户端向Data Protector备份域服务器的dpwinsup.dll模块发送了特制报文,就可能泄露任意内存,导致运行在3817/TCP端口上的dpwingad进程崩溃。 ; Buggy code @dpwinsup module of dpwingad process ; running at 3817/TCP port ; dpwinsup.10275F80 100DDE89 8B15 54A72210 MOV EDX,DWORD PTR DS:[1022A754] 100DDE8F 8B82 98650000 MOV EAX,DWORD PTR DS:[EDX+6598] ; ECX = user controlled data 100DDE95 8B4C24 54 MOV ECX,DWORD PTR SS:[ESP+54] ; EDX = if invalid/valid offset 100DDE99 8D1481 LEA EDX,DWORD PTR DS:[ECX+EAX*4] ; Crash/Memory Leak 100DDE9C 8B3495 F0A42210 MOV ESI,DWORD PTR DS:[EDX*4+1022A4F0] 100DDEA3 83C4 1C ADD ESP,1C 100DDEA6 897424 10 MOV DWORD PTR SS:[ESP+10],ESI HP Data Protector Express SSE 4.x HP Data Protector Express SSE 3.x HP Data Protector Express 4.x HP Data Protector Express 3.x 厂商补丁: HP -- HP已经为此发布了一个安全公告(HPSBMA02417)以及相应补丁: HPSBMA02417:SSRT090031 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code 链接:<a href="http://alerts.hp.com/r?2.1.3KT.2ZR.zWmfi.DEO%5f5w..T.HP34.1soQ.bW89MQ%5f%5fDCPWFQR0" target="_blank" rel=external nofollow>http://alerts.hp.com/r?2.1.3KT.2ZR.zWmfi.DEO%5f5w..T.HP34.1soQ.bW89MQ%5f%5fDCPWFQR0</a> id SSV:11691 last seen 2017-11-19 modified 2009-06-24 published 2009-06-24 reporter Root title HP Data Protector dpwinsup.dll内存泄漏漏洞 bulletinFamily exploit description No description provided by source. id SSV:11689 last seen 2017-11-19 modified 2009-06-24 published 2009-06-24 reporter Root source https://www.seebug.org/vuldb/ssvid-11689 title HP Data Protector 4.00-SP1b43064 Remote Memory Leak/Dos (meta) bulletinFamily exploit description No description provided by source. id SSV:66661 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-66661 title HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Dos (meta)
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543
- http://ivizsecurity.com/security-advisory-iviz-sr-09002.html
- http://secunia.com/advisories/35084
- http://www.securityfocus.com/bid/34955
- http://www.securitytracker.com/id?1022220
- http://www.vupen.com/english/advisories/2009/1309
- https://www.exploit-db.com/exploits/9006
- https://www.exploit-db.com/exploits/9007