Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow

Subscribe

Check Point Reference: CPAI-2010-139
Date Published:
Severity:
Source: Secunia Advisory SA37845
Industry Reference(s):

CVE-2007-2281

Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
HP OpenView Data Protector Application Recovery Manager 5.5
HP OpenView Data Protector Application Recovery Manager 6.0
Vulnerability Description
A buffer overflow vulnerability exists in HP OpenView Data Protector Cell Manager, a backup solution designed for enterprise and distributed environments. The flaw is due to an integer overflow while processing crafted packets received on port 1530/TCP. A remote attacker can exploit this vulnerability by sending maliciously crafted packets to the affected service.
Update/Patch Available
Vendor's advisory
Vulnerability Details
The vulnerability is due to an integer overflow that occurs while processing crafted requests. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted request to a target server, potentially leading to execution of arbitrary code.

Protection Overview

The protection detect and block attempts to send commands to the HP Cell Manager with invalid length specified.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Enterprise Software, and select the HP OpenView Network Node Manager protection group.
3. Click HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: HP OpenView Network Node Manager
Description: HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow