RULE(RULE ID:322940)

Rule General Information
Release Date: 2019-08-22
Rule Name: HP OpenView Network Node Manager Sprintf Buffer Overflow Vulnerability (CVE-2010-1961)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:40638
http://marc.info/?l=bugtraq&m=127602909915281&w=2
http://www.securityfocus.com/archive/1/511731/100/0/threaded
SecurityTrackerID:1024071
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.zerodayinitiative.com/advisories/ZDI-10-106/