Update Protection against HP OpenView Network Node Manager ovalarm.exe Accept-Language Buffer Overflow Vulnerability
| Check Point Reference: | CPAI-2009-314 | |
| Date Published: | ||
| Severity: | ||
| Source: | Secunia Advisory: 37665 | |
| Industry Reference(s): | ||
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? HP OpenView Network Node Manager (OV NNM) 7.01 HP OpenView Network Node Manager (OV NNM) 7.51 HP OpenView Network Node Manager (OV NNM) 7.53 | ||
| Vulnerability Description A stack buffer overflow exists in HP OpenView Network Node Manager (NNM) CGI program ovalarm.exe. The vulnerability is due to a boundary error when processing Accept-Language HTTP header and the OvAcceptLang cookie value in a crafted HTTP request. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to a target server. |
||
|
Update/Patch Available HP has released an advisory addressing this vulnerability: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877 |
|
|
Vulnerability Details The vulnerability exists due to insufficient boundary checking when handling the Accept-Language HTTP header and OvAcceptLang Cookie values. |
Protection Overview This protection will detect and block HTTP requests with Accept-Language parameters whose length exceeds a threshold and requests for the HP OpenView CGI binary Toolbar.exe with long cookie parameters.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.