RULE(RULE ID:305349)

Rule General Information
Release Date: 2013-03-29
Rule Name: HP OpenView NNM getnnmdata.exe CGI Hostname Parameter Buffer Overflow Vulnerability (CVE-2010-1555)
Severity:
CVE ID:
Rule Protection Details
Description: A buffer overflow vulnerability exists in HP OpenView Network Node Manager (NNM). The vulnerability is due to a boundary error in getnnmdata.exe when processing the Hostname variable sent in a crafted HTTP request. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to a target server, potentially causing arbitrary code to be injected and executed in the security context of the getnnmdata.exe process.
Impact: Remote code execution
Affected OS: Windows
Reference: CVE-2010-1555
ZeroDayInitiative:ZDI-10-086
SecurityAdvisory:SA39757
SecurityFocusBID:40072
msf
Solutions
Update vendor's patch.