HP OpenView Operations OVTrace buffer overflow

Added: 08/16/2007
CVE: CVE-2007-3872
BID: 25255
OSVDB: 39527

Background

HP OpenView Operations is event management and performance monitoring software.

Problem

A buffer overflow vulnerability in HP OpenView Operations allows remote attackers to execute arbitrary commands by sending a specially crafted request to the OVTrace service.

Resolution

See TPTI-07-14 for fix information.

References

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=574

Limitations

Exploit works on HP OpenView Internet Service (OVIS) 6.00.081.

Platforms

Windows 2000
Windows Server 2003

Back to exploit index