Vulnerabilities > CVE-2009-4179 - Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Accept-Language header in an OVABverbose action.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 12 |
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Buffer Overflow via Environment Variables This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the attacker finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.
- Overflow Buffers Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an attacker. As a consequence, an attacker is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the attackers' choice.
- Client-side Injection-induced Buffer Overflow This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malicious content from a custom-built hostile service.
- Filter Failure through Buffer Overflow In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
- MIME Conversion An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME system is designed to allow various different information formats to be interpreted and sent via e-mail. Attack points exist when data are converted to MIME compatible format and back.
Exploit-Db
description HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow. CVE-2009-4179. Remote exploit for windows platform id EDB-ID:16797 last seen 2016-02-02 modified 2010-11-11 published 2010-11-11 reporter metasploit source https://www.exploit-db.com/download/16797/ title HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow description HP NNM 7.53 ovalarm.exe CGI Pre Authentication Remote Buffer Overflow. CVE-2009-4179. Remote exploit for windows platform id EDB-ID:10394 last seen 2016-02-01 modified 2009-12-12 published 2009-12-12 reporter sinn3r and muts source https://www.exploit-db.com/download/10394/ title HP NNM 7.53 ovalarm.exe CGI Pre Authentication Remote Buffer Overflow
Metasploit
description | This module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.53. By sending a specially crafted CGI request to ovalarm.exe, an attacker can execute arbitrary code. This specific vulnerability is due to a call to "sprintf_new" in the "isWide" function within "ovalarm.exe". A stack buffer overflow occurs when processing an HTTP request that contains the following. 1\. An "Accept-Language" header longer than 100 bytes 2\. An "OVABverbose" URI variable set to "on", "true" or "1" The vulnerability is related to "_WebSession::GetWebLocale()". NOTE: This exploit has been tested successfully with a reverse_ord_tcp payload. |
id | MSF:EXPLOIT/WINDOWS/HTTP/HP_NNM_OVALARM_LANG |
last seen | 2020-03-17 |
modified | 2017-09-14 |
published | 2010-01-22 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/hp_nnm_ovalarm_lang.rb |
title | HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow |
Nessus
NASL family HP-UX Local Security Checks NASL id HPUX_PHSS_40374.NASL description s700_800 11.X OV NNM7.53 PA-RISC Intermediate Patch 25 : The remote HP-UX host is affected by multiple vulnerabilities : - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2009-0898 (SSRT090101) CVE-2009-3845 (SSRT090037, ZDI-CAN-453) CVE-2009-3846 (SSRT090122, ZDI-CAN-526) CVE-2009-3847 (SSRT090128, ZDI-CAN-532) CVE-2009-3848 (SSRT090129, ZDI-CAN-522) CVE-2009-3849 (SSRT090130, ZDI-CAN-523) CVE-2009-4176 (SSRT090131, ZDI-CAN-532) CVE-2009-4177 (SSRT090132, ZDI-CAN-538) CVE-2009-4178 (SSRT090133, ZDI-CAN-539) CVE-2009-4179 (SSRT090134, ZDI-CAN-540) CVE-2009-4180 (SSRT090135, ZDI-CAN-542) CVE-2009-4181 (SSRT090164, ZDI-CAN-549). (HPSBMA02483 SSRT090257) - Potential security vulnerabilities have been identified with the Java Runtime Environment (JRE) and Java Developer Kit (JDK) delivered with HP OpenView Network Node Manager (OV NNM). These vulnerabilities may allow remote unauthorized access, privilege escalation, execution of arbitrary code, and creation of a Denial of Service (DoS) . (HPSBMA02486 SSRT090049) last seen 2020-06-01 modified 2020-06-02 plugin id 43142 published 2009-12-14 reporter This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/43142 title HP-UX PHSS_40374 : s700_800 11.X OV NNM7.53 PA-RISC Intermediate Patch 25 code # # (C) Tenable Network Security, Inc. # # The descriptive text and patch checks in this plugin were # extracted from HP patch PHSS_40374. The text itself is # copyright (C) Hewlett-Packard Development Company, L.P. # if (NASL_LEVEL < 3000) exit(0); include("compat.inc"); if (description) { script_id(43142); script_version("1.38"); script_cvs_date("Date: 2018/07/12 19:01:15"); script_cve_id("CVE-2008-2086", "CVE-2008-5339", "CVE-2008-5340", "CVE-2008-5341", "CVE-2008-5342", "CVE-2008-5343", "CVE-2008-5344", "CVE-2008-5345", "CVE-2008-5347", "CVE-2008-5348", "CVE-2008-5350", "CVE-2008-5351", "CVE-2008-5353", "CVE-2008-5354", "CVE-2008-5356", "CVE-2008-5357", "CVE-2008-5358", "CVE-2008-5359", "CVE-2008-5360", "CVE-2009-0898", "CVE-2009-3845", "CVE-2009-3846", "CVE-2009-3847", "CVE-2009-3848", "CVE-2009-3849", "CVE-2009-4176", "CVE-2009-4177", "CVE-2009-4178", "CVE-2009-4179", "CVE-2009-4180", "CVE-2009-4181"); script_xref(name:"HP", value:"emr_na-c01950877"); script_xref(name:"HP", value:"emr_na-c02000725"); script_xref(name:"HP", value:"SSRT090049"); script_xref(name:"HP", value:"SSRT090257"); script_name(english:"HP-UX PHSS_40374 : s700_800 11.X OV NNM7.53 PA-RISC Intermediate Patch 25"); script_summary(english:"Checks for the patch in the swlist output"); script_set_attribute( attribute:"synopsis", value:"The remote HP-UX host is missing a security-related patch." ); script_set_attribute( attribute:"description", value: "s700_800 11.X OV NNM7.53 PA-RISC Intermediate Patch 25 : The remote HP-UX host is affected by multiple vulnerabilities : - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2009-0898 (SSRT090101) CVE-2009-3845 (SSRT090037, ZDI-CAN-453) CVE-2009-3846 (SSRT090122, ZDI-CAN-526) CVE-2009-3847 (SSRT090128, ZDI-CAN-532) CVE-2009-3848 (SSRT090129, ZDI-CAN-522) CVE-2009-3849 (SSRT090130, ZDI-CAN-523) CVE-2009-4176 (SSRT090131, ZDI-CAN-532) CVE-2009-4177 (SSRT090132, ZDI-CAN-538) CVE-2009-4178 (SSRT090133, ZDI-CAN-539) CVE-2009-4179 (SSRT090134, ZDI-CAN-540) CVE-2009-4180 (SSRT090135, ZDI-CAN-542) CVE-2009-4181 (SSRT090164, ZDI-CAN-549). (HPSBMA02483 SSRT090257) - Potential security vulnerabilities have been identified with the Java Runtime Environment (JRE) and Java Developer Kit (JDK) delivered with HP OpenView Network Node Manager (OV NNM). These vulnerabilities may allow remote unauthorized access, privilege escalation, execution of arbitrary code, and creation of a Denial of Service (DoS) . (HPSBMA02486 SSRT090049)" ); # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877 script_set_attribute( attribute:"see_also", value:"http://www.nessus.org/u?422f4693" ); # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02000725 script_set_attribute( attribute:"see_also", value:"http://www.nessus.org/u?72ecd727" ); script_set_attribute( attribute:"solution", value:"Install patch PHSS_40374 or subsequent." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C"); script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C"); script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available"); script_set_attribute(attribute:"exploit_available", value:"true"); script_set_attribute(attribute:"exploit_framework_core", value:"true"); script_set_attribute(attribute:"exploited_by_malware", value:"true"); script_set_attribute(attribute:"metasploit_name", value:'HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow'); script_set_attribute(attribute:"exploit_framework_metasploit", value:"true"); script_set_attribute(attribute:"exploit_framework_canvas", value:"true"); script_set_attribute(attribute:"canvas_package", value:'White_Phosphorus'); script_cwe_id(94, 119, 189, 200, 264); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux"); script_set_attribute(attribute:"patch_publication_date", value:"2009/11/26"); script_set_attribute(attribute:"patch_modification_date", value:"2010/02/12"); script_set_attribute(attribute:"plugin_publication_date", value:"2009/12/14"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2009-2018 Tenable Network Security, Inc."); script_family(english:"HP-UX Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("hpux.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX"); if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING); if (!hpux_check_ctx(ctx:"11.11 11.23 11.31", proc:"parisc")) { exit(0, "The host is not affected since PHSS_40374 applies to a different OS release / architecture."); } patches = make_list("PHSS_40374", "PHSS_40707", "PHSS_41242", "PHSS_41606", "PHSS_41857", "PHSS_42232", "PHSS_43046", "PHSS_43353"); foreach patch (patches) { if (hpux_installed(app:patch)) { exit(0, "The host is not affected because patch "+patch+" is installed."); } } flag = 0; if (hpux_check_patch(app:"OVNNMETCore.OVNNMET-CORE", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMETCore.OVNNMET-IPV6", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMETCore.OVNNMET-JPN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMETCore.OVNNMET-PD", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMETCore.OVNNMET-PESA", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVMIB-CONTRIB", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVNNM-RUN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVNNMGR-JPN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVNNMGR-KOR", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVNNMGR-SCH", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVRPT-RUN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVWWW-JPN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVWWW-KOR", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgr.OVWWW-SCH", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgrMan.OVNNM-RUN-MAN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVNNMgrRtDOC.OVNNM-ENG-DOC", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVDB-RUN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVEVENT-MIN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVMIN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVPMD-MIN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVSNMP-MIN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVWIN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVWWW-EVNT", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVWWW-FW", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatform.OVWWW-SRV", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatformMan.OVEVENTMIN-MAN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatformMan.OVMIN-MAN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatformMan.OVSNMP-MIN-MAN", version:"B.07.50.00")) flag++; if (hpux_check_patch(app:"OVPlatformMan.OVWIN-MAN", version:"B.07.50.00")) flag++; if (flag) { if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get()); else security_hole(0); exit(0); } else audit(AUDIT_HOST_NOT, "affected");
NASL family HP-UX Local Security Checks NASL id HPUX_PHSS_40375.NASL description s700_800 11.X OV NNM7.53 IA-64 Intermediate Patch 25 : The remote HP-UX host is affected by multiple vulnerabilities : - Potential security vulnerabilities have been identified with the Java Runtime Environment (JRE) and Java Developer Kit (JDK) delivered with HP OpenView Network Node Manager (OV NNM). These vulnerabilities may allow remote unauthorized access, privilege escalation, execution of arbitrary code, and creation of a Denial of Service (DoS) . (HPSBMA02486 SSRT090049) - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2009-0898 (SSRT090101) CVE-2009-3845 (SSRT090037, ZDI-CAN-453) CVE-2009-3846 (SSRT090122, ZDI-CAN-526) CVE-2009-3847 (SSRT090128, ZDI-CAN-532) CVE-2009-3848 (SSRT090129, ZDI-CAN-522) CVE-2009-3849 (SSRT090130, ZDI-CAN-523) CVE-2009-4176 (SSRT090131, ZDI-CAN-532) CVE-2009-4177 (SSRT090132, ZDI-CAN-538) CVE-2009-4178 (SSRT090133, ZDI-CAN-539) CVE-2009-4179 (SSRT090134, ZDI-CAN-540) CVE-2009-4180 (SSRT090135, ZDI-CAN-542) CVE-2009-4181 (SSRT090164, ZDI-CAN-549). (HPSBMA02483 SSRT090257) last seen 2020-06-01 modified 2020-06-02 plugin id 43143 published 2009-12-14 reporter This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/43143 title HP-UX PHSS_40375 : s700_800 11.X OV NNM7.53 IA-64 Intermediate Patch 25 NASL family HP-UX Local Security Checks NASL id HPUX_PHSS_40705.NASL description s700_800 11.11 OV NNM7.01 Intermediate Patch 13 : The remote HP-UX host is affected by multiple vulnerabilities : - A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to execute arbitrary code. (HPSBMA02424 SSRT080125) - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2009-0898 (SSRT090101) CVE-2009-3845 (SSRT090037, ZDI-CAN-453) CVE-2009-3846 (SSRT090122, ZDI-CAN-526) CVE-2009-3847 (SSRT090128, ZDI-CAN-532) CVE-2009-3848 (SSRT090129, ZDI-CAN-522) CVE-2009-3849 (SSRT090130, ZDI-CAN-523) CVE-2009-4176 (SSRT090131, ZDI-CAN-532) CVE-2009-4177 (SSRT090132, ZDI-CAN-538) CVE-2009-4178 (SSRT090133, ZDI-CAN-539) CVE-2009-4179 (SSRT090134, ZDI-CAN-540) CVE-2009-4180 (SSRT090135, ZDI-CAN-542) CVE-2009-4181 (SSRT090164, ZDI-CAN-549). (HPSBMA02483 SSRT090257) - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to allow execution of arbitrary code. (HPSBMA02400 SSRT080144) - Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). The vulnerabilities could be exploited remotely to execute arbitrary code. (HPSBMA02416 SSRT090008) - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2010-1550 (SSRT090225, ZDI-CAN-563) CVE-2010-1551 (SSRT090226, ZDI-CAN-564) CVE-2010-1552 (SSRT090227, ZDI-CAN-566) CVE-2010-1553 (SSRT090228, ZDI-CAN-573) CVE-2010-1554 (SSRT090229, ZDI-CAN-574) CVE-2010-1555 (SSRT090230, ZDI-CAN-575). (HPSBMA02527 SSRT010098) - A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to execute arbitrary code. (HPSBMA02425 SSRT080091) last seen 2020-06-01 modified 2020-06-02 plugin id 46261 published 2010-05-10 reporter This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/46261 title HP-UX PHSS_40705 : s700_800 11.11 OV NNM7.01 Intermediate Patch 13
Packetstorm
data source | https://packetstormsecurity.com/files/download/85494/hp_nnm_ovalarm_lang.rb.txt |
id | PACKETSTORM:85494 |
last seen | 2016-12-05 |
published | 2010-01-22 |
reporter | jduck |
source | https://packetstormsecurity.com/files/85494/HP-OpenView-Network-Node-Manager-ovalarm.exe-CGI-Buffer-Overflow.html |
title | HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow |
Saint
bid 37261 description HP OpenView Network Node Manager ovalarm.exe Accept-Language buffer overflow id net_ovnodemgralarmlangbo osvdb 60930 title openview_nnm_ovalarm_accept_language type remote bid 37261 description HP OpenView Network Node Manager ovwebsnmpsrv.exe buffer overflow via jovgraph.exe id net_ovwebsnmpsrvbo osvdb 60932 title openview_nnm_ovwebsnmpsrv_jovgraph type remote
Seebug
bulletinFamily | exploit |
description | HP OpenView Network Node Manager是一款HP公司开发和维护的网络管理系统软件,具有强大的网络节点管理功能。 HP OpenView Network Node Manager存在多个安全漏洞: CVE-2009-3845: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 Network Node Manager (NNM)分发的PERL CGI可执行程序存在缺陷,应用程序不正确过滤提交给监听TCP 3443端口的NNM HTTP服务器的hostname HTTP变量,通过提供管道操作符,恶意攻击者可以注入任意命令并在远程服务器上执行。 CVE-2009-3849: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 nnmRptConfig.exe CGI可执行程序可通过监听在80端口的IIS WEB服务器访问,当解析POST变量时,进程使用strcat调用拷贝Template参数到固定栈缓冲区大小,提供超大值可触发缓冲区溢出并导致任意代码执行。 CVE-2009-3848: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 nnmRptConfig.exe CGI可执行程序可通过监听在80端口的IIS WEB服务器访问,当解析POST变量时,进程使用vsprintf()调用拷贝Template参数到固定栈缓冲区大小,提供超大值可触发缓冲区溢出并导致任意代码执行。 CVE-2009-3849: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 snmp.exe CGI可执行程序可通过监听在80端口的IIS WEB服务器访问,当解析POST变量时,进程使用sprintf()调用拷贝Oid参数到固定栈缓冲区大小,提供超大值可触发缓冲区溢出并导致任意代码执行。 CVE-2009-4179: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 ovalarm.exe CGI应用程序存在缺陷,如果设置了OVABverbose POST变量,进程会获取Accept-Language HTTP头字段的值并没有任何长度检查就拷贝到0x100字节栈缓冲区,提供超长字符串可溢出缓冲区,导致任意代码执行。 CVE-2009-3846: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 CNCVE-20093846 ovlogin.exe CGI应用程序存在缺陷,在验证过程中userid和passwd post变量会传递给这个CGI,并通过sprintf()调用拷贝到静态0x100字节堆缓冲区,提供超长字符串可溢出这个缓冲区导致任意代码执行。 CVE-2009-4176: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 CNCVE-20093846 CNCVE-20094176 ovsessionmgr.exe应用程序存在缺陷,会话管理器从ovlogin.exe CGI应用程序发送的POST变量中获取凭证信息,'userid'和'passwd'变量通过sprintf()调用拷贝到静态0x100字节堆缓冲区,提供超长字符串可溢出这个缓冲区导致任意代码执行。 CVE-2009-4178: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 CNCVE-20093846 CNCVE-20094176 CNCVE-20094178 OvWebHelp.exe CGI应用程序存在缺陷,在字符串串联过程中。进程获取Topic POST变量值并没有任何长度检查拷贝到0x400字节堆缓冲区中,提供超长字符串可溢出这个缓冲区导致任意代码执行。 CVE-2009-4181: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 CNCVE-20093846 CNCVE-20094176 CNCVE-20094178 CNCVE-20094181 jovgraph.exe CGI应用程序接收到请求时会启用ovwebsnmpsrv.exe应用程序,ovwebsnmpsrv.exe应用程序存在漏洞,进程会拷贝'sel' POST变量内容以用户可控的次数拷贝数据到静态栈缓冲区中,通过重复特定字符串作为'arg' POST变量内容,可溢出此缓冲区导致任意代码执行。 CVE-2009-4180: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 CNCVE-20093846 CNCVE-20094176 CNCVE-20094178 CNCVE-20094181 CNCVE-20094180 snmpviewer.exe CGI应用程序存在设计缺陷,进程使用strcat调用把HTTP请求中的HOST头字段数据拷贝到固定长度的缓冲区中,提供超长字符串可溢出这个缓冲区导致任意代码执行。 CVE-2009-4177: CNCVE ID:CNCVE-20090898 CNCVE-20093845 CNCVE-20093846 CNCVE-20093849 CNCVE-20093848 CNCVE-20094176 CNCVE-20094177 CNCVE-20094178 CNCVE-20094179 CNCVE-20094180 CNCVE-20094181 CNCVE-20093847 CNCVE-20093845 CNCVE-20093849 CNCVE-20093848 CNCVE-20093849 CNCVE-20094179 CNCVE-20093846 CNCVE-20094176 CNCVE-20094178 CNCVE-20094181 CNCVE-20094180 CNCVE-20094177 webappmon.exe CGI应用程序存在设计缺陷,进程使用strcat调用把HTTP请求中的HOST头字段数据拷贝到位于.DATA段中的固定长度缓冲区中,提供超长字符串可溢出这个缓冲区导致任意代码执行。 HP OpenView Network Node Manager 7.50 Windows 2000/XP HP OpenView Network Node Manager 7.50 Solaris HP OpenView Network Node Manager 7.50 Linux HP OpenView Network Node Manager 7.50 HP-UX 11.X HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.01 用户可参考如下安全公告获得补丁信息: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877 |
id | SSV:15058 |
last seen | 2017-11-19 |
modified | 2009-12-14 |
published | 2009-12-14 |
reporter | Root |
title | HP OpenView Network Node Manager多个远程代码执行漏洞 |
References
- http://dvlabs.tippingpoint.com/advisory/TPTI-09-12
- http://dvlabs.tippingpoint.com/advisory/TPTI-09-12
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877
- http://marc.info/?l=bugtraq&m=126046355120442&w=2
- http://marc.info/?l=bugtraq&m=126046355120442&w=2
- http://www.securityfocus.com/archive/1/508355/100/0/threaded
- http://www.securityfocus.com/archive/1/508355/100/0/threaded
- http://www.securityfocus.com/bid/37261
- http://www.securityfocus.com/bid/37261
- http://www.securityfocus.com/bid/37347
- http://www.securityfocus.com/bid/37347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54657
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54657