Preemptive Protection against HP OpenView Network Node Manager snmpviewer.exe Host Header Buffer Overflow
| Check Point Reference: | CPAI-2009-310 | |
| Date Published: | ||
| Preemptive Since: | ||
| Severity: | ||
| Source: | Secunia Advisory: SA37665 | |
| Industry Reference(s): | CVE-2009-4180 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? HP OpenView Network Node Manager (OV NNM) 7.01 HP OpenView Network Node Manager (OV NNM) 7.51 HP OpenView Network Node Manager (OV NNM) 7.53 | ||
| Vulnerability Description A buffer overflow vulnerability exists in the HP OpenView Network Node Manager (NNM) CGI program snmpviewer.exe. The vulnerability is due to a boundary error when processing the Host header from HTTP requests. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to a target server, potentially causing arbitrary code injection and execution. |
||
|
Update/Patch Available HP has released an advisory addressing this vulnerability: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877 |
|
|
Vulnerability Details HP OpenView Network Node Manager (NNM) supplies several CGI applications to provide management interface of the NNM server. The vulnerability is caused by insufficient boundary checking when handling the Host HTTP header. |
Protection Overview
Security Gateway R70 and IPS-1 will detect and block HTTP requests with host headers that are longer than 128 bytes. No update is required to address this vulnerability.
To configure the defense, select your product from the list below and follow the related protection steps.