Release date: 2011-10-19
Updated on: 2011-10-19
Affected Systems:
HP Data Protector Notebook extension6.20
HP Data Protector for Personal Computers 7.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50181
Cve id: CVE-2011-3156, CVE-2011-3157, CVE-2011-3158, CVE-2011-3159, CVE-2011-3160, CVE-2011-3161
HP Data Protector Notebook Extension is a laptop backup software.
HP Data Protector Notebook Extension has a remote code execution vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Andrea Micalizzi aka rgod
Link: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay? DocId = emr_na-c02964430
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HP
--
HP has released a Security Bulletin (hpsbmp 02713) and corresponding patches for this:
Hpsbmp 02713: HP Data Protector Notebook Extension, Remote Execution of Arbitrary Code
Link: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay? DocId = emr_na-c02964430