安全研究

安全漏洞
HP OpenView Operations  OVTrace多个远程栈溢出漏洞

发布日期:2007-08-09
更新日期:2007-08-14

受影响系统:
HP Openview Operations for Windows A.07.50
描述:
BUGTRAQ  ID: 25255
CVE(CAN) ID: CVE-2007-3872

OpenView Operations软件是一组网络管理工具,用于监控网络中的事件并评估主机性能。

OpenView Operations的OVTrace组件处理用户请求时存在多个缓冲区溢出漏洞,远程攻击者可能利用此漏洞控制服务器。

OVTrace组件负责处理用户请求的函数将请求中的字符串拷贝到了固定大小的缓冲区,由于没有正确地验证长度,因此可能触发栈溢出,导致以系统权限执行任意代码。

<*来源:Cody Pierce
  
  链接:http://secunia.com/advisories/26394/
        http://marc.info/?l=bugtraq&m=118713314204403&w=2
        http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=574
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01109171&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01106515&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01115068&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01114023&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01114156&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01112038&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01111851&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01110627&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01110576&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01109617&printver
        http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01109584&printver
*>

建议:
厂商补丁:

HP
--
HP已经为此发布了一个安全公告(HPSBMA02237)以及相应补丁:
HPSBMA02237:SSRT061260 rev.1 - HP OpenView Performance Agent (OVPA) Running Shared Trace Service, Remote Arbitrary Code Execution
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?print=true&objectID=c01109584&printver

浏览次数:2482
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障