Release date:
Updated on:
Affected Systems:
HP LoadRunner 9.52
HP LoadRunner 9.1
HP LoadRunner 9.0
HP LoadRunner 8.1.0.0 build 1735
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48073
LoadRunner is a load testing tool that predicts system behavior and performance.
The remote buffer overflow vulnerability of the virtual user script file exists in the implementation of HP LoadRunner. Remote attackers can exploit this vulnerability to execute arbitrary code through the affected application, resulting in DOS.
When parsing a. usr file that contains a long instruction string, the application may crash.
<* Source: Jeremy Brown
Link: http://www.kb.cert.org/vuls/id/987308
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HP
--
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://itrc.hp.com