CVE-2007-6204
Hewlett-Packard OpenView Network Node Manager Multiple CGI Buffer Overflow Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.
Múltiples desbordamientos de búfer en la región stack de la memoria en HP OpenView Network Node Manager (OV NNM) versiones 6.41, 7.01 y 7.51, permiten a los atacantes remotos ejecutar código arbitrario por medio de argumentos largos no especificados en los archivos (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe y (4) webappmon.exe, como es demostrado por medio de un parámetro action largo en el archivo OpenView5.exe.
These vulnerabilities allow remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard (HP) OpenView Network Node Manager (NNM). Authentication is not required to exploit these vulnerabilities.
The specific flaws exists within the CGI applications that handle the management of the NNM server. Due to lack of bounds checking during a call to sprintf(), sending overly long arguments to the various CGI variables result in a classic stack overflow leading to compromise of the remote server. Exploitation leads to code execution running under the credentials of the web server. Further techniques can be leveraged to gain full SYSTEM access.
The following is a list of vulnerable CGI applications:
- ovlogin.exe- OpenView5.exe- snmpviewer.exe- webappmon.exe
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-12-03 CVE Reserved
- 2007-12-06 CVE Published
- 2010-05-09 First Exploit
- 2024-08-07 CVE Updated
- 2024-09-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/3441 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/484704/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019055 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-07-071.html | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38892 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16805 | 2010-05-09 | |
https://www.exploit-db.com/exploits/4724 | 2024-08-07 | |
http://www.securityfocus.com/bid/26741 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01188923 | 2018-10-15 | |
http://secunia.com/advisories/27964 | 2018-10-15 | |
http://www.vupen.com/english/advisories/2007/4111 | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 6.41 Search vendor "Hp" for product "Openview Network Node Manager" and version "6.41" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.0.1 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.0.1" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.51 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.51" | - |
Affected
|