Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against HP OpenView Network Node Manager rping Stack Buffer Overflow

Subscribe

Check Point Reference: CPAI-2009-201
Date Published:
Severity:
Source: Secunia Advisory: 35408
Industry Reference(s):

CVE-2009-1420

Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
HP OpenView Network Node Manager 7.51
HP OpenView Network Node Manager 7.53 prior to rev. 1.30.009
Vulnerability Description
A buffer overflow vulnerability exists in HP Network Node Manager, a software application designed for management, maintenance and monitoring of networks and network devices. The flaw is due to a boundary error when processing crafted packets sent to the server. Remote attackers could exploit this vulnerability by sending a crafted HTTP request to the affected TCP port. The vulnerability could allow remote attackers to execute arbitrary code on a vulnerable system.
Vulnerability Details
The vulnerability exists due to insufficient boundary checks when handling overly long hostname values. Remote attackers could exploit this vulnerability by sending a carefully crafted packet to a vulnerable HP OpenView Network Node Manager server.

Protection Overview
By enabling this protection, IPS-1 will detect and block CGI requests to the HP OpenView server's rping utility with invalid hostnames.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Web Intelligence > WWW 2, and select the CGI Attacks protection group.
3. Click HP OpenView rping application attack (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entry will be logged:

Alert Name: WWW/CGI Attacks Protection Group
Description: HP OpenView rping application attack