RULE(RULE ID:322444)

Rule General Information
Release Date: 2019-07-06
Rule Name: HP Openview Network Node Manager ovlaunch HTTP Request Buffer Overflow Vulnerability (CVE-2008-4562)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in the ovlaunch CGI program in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 on Windows allows remote attackers to execute arbitrary code via a crafted Host parameter. NOTE: this issue may be partially covered by CVE-2009-0205.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01661610
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=772
Solutions
Refer to the announcement or patch by the vendor: http://alerts.hp.com/r