Release date:
Updated on:
Affected Systems:
HP OpenView Network Node Manager
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3167
HP OpenView Network Node Manager is a Network management and backup software.
HP OpenView Network Node Manager in ov. dll implementation has a security vulnerability. when processing the textFile option file name, the boundary check vulnerability exists before providing values for format strings in _ OVBuildPath, which can cause stack overflow and memory corruption, attackers can execute arbitrary code in the target service.
<* Source: Aniway
Link: http://www.zerodayinitiative.com/advisories/ZDI-12-002/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HP
--
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://itrc.hp.com