CVE-2008-1842

Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.
Configurations

Configuration 1

cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:4.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.41:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.20:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:8.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:5.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.31:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.10:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.50:*:*:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:6.4:*:*:*:*:*:*:*

Information

Published : 2008-04-16 05:05

Updated : 2018-10-11 08:37


NVD link : CVE-2008-1842

Mitre link : CVE-2008-1842

Products Affected
No products.
CWE