First published: Fri Dec 18 2009(Updated: )
Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Storage Data Protector Cell Manager | =6.0 | |
HP OpenView Storage Data Protector Cell Manager | =5.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2281 has a high severity rating due to its potential for remote code execution.
To fix CVE-2007-2281, upgrade to the latest version of HP OpenView Storage Data Protector that does not contain the vulnerability.
CVE-2007-2281 specifically affects HP OpenView Storage Data Protector versions 5.50 and 6.0.
CVE-2007-2281 can be exploited by remote attackers who can send crafted packets to the affected service.
CVE-2007-2281 is categorized as an integer overflow vulnerability.