CVE-2008-1842: Buffer Overflow
Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1842?
CVE-2008-1842 is considered to have a critical severity due to the potential for denial of service and arbitrary code execution.
How do I fix CVE-2008-1842?
To fix CVE-2008-1842, ensure that you upgrade HP OpenView Network Node Manager to a version higher than 8.01 or the patched versions recommended by HP.
Which versions of HP OpenView Network Node Manager are affected by CVE-2008-1842?
CVE-2008-1842 affects HP OpenView Network Node Manager versions up to and including 8.01, as well as various earlier versions.
What type of attack does CVE-2008-1842 enable?
CVE-2008-1842 allows remote attackers to perform denial of service attacks or execute arbitrary code via specifically crafted requests.
Is there a way to mitigate the risk of CVE-2008-1842 without upgrading?
Temporary mitigation for CVE-2008-1842 can be achieved by implementing network security measures, such as firewalls or access controls, to restrict access to TCP port 8886.