Get a Pentest and security assessment of your IT network.

Advisories

HP OpenView NNM snmpviewer.exe CGI Host Header Stack Overflow

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard OpenView Network Node Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the snmpviewer.exe CGI application. This process copies the Host header from HTTP requests into a fixed-length buffer located on the stack via a call to strcat. By specifying a string length within a certain range this buffer can be overflowed leading to arbitrary code execution.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83667/TPTI-09-13.txt

Source: https://packetstormsecurity.com/files/83667/HP-OpenView-NNM-snmpviewer.exe-CGI-Host-Header-Stack-Overflow.html

Related posts
Advisories

CSIS2005-1.txt

Advisories

Secunia Security Advisory 17625

Advisories

Secunia Security Advisory 20411

Advisories

Secunia Security Advisory 23300