RULE(RULE ID:805943)

Rule General Information
Release Date: 2021-03-26
Rule Name: HP Intelligent Management Center dbman Buffer Overflow Vulnerability (CVE-2011-1850)
Severity:
CVE ID:
Rule Protection Details
Description: A buffer overflow vulnerability has been identified in the dbman component of the HP Intelligent Management Center. While processing packets sent to port 2810/UDP, user-supplied data is copied to a stack buffer by calling the sprintf function without performing a boundary check. By sending a crafted packet to the target, a remote attacker can exploit this vulnerability to execute arbitrary code under the security context of the SYSTEM user. If the attack is unsuccessful, the application may terminate unexpectedly.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:47789
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02822750
SecurityTrackerID:1025519
ZeroDayInitiative:ZDI-11-162
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.