Release date:
Updated on:
Affected Systems:
HP OpenView Network Node Manager
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3166
HP OpenView Network Node Manager is a Network management and backup software.
HP OpenView Network Node managerhas a security vulnerability in the implementation of the webappmon.exe CGI program. when processing specially crafted parameters, the boundary check vulnerability exists before providing values to format strings, which can cause stack overflow and memory corruption, attackers can execute arbitrary code in the target service.
<* Source: Aniway
Link: http://www.zerodayinitiative.com/advisories/ZDI-12-003
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HP
--
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://itrc.hp.com