CVE-2008-2438: Buffer Overflow
Published Apr 28, 2009
·Updated
Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.
Affected Software
3 affected components
Hewlett Packard OpenView Network Node Manager=7.01
Hewlett Packard OpenView Network Node Manager=7.51
Hewlett Packard OpenView Network Node Manager=7.53
Remediation
Patch Available
Event History
Apr 28, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2438?
CVE-2008-2438 is a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2008-2438?
To fix CVE-2008-2438, upgrade your HP OpenView Network Node Manager to a patched version that addresses this vulnerability.
3
What are the affected versions for CVE-2008-2438?
CVE-2008-2438 affects HP OpenView Network Node Manager versions 7.01, 7.51, and 7.53.
4
What type of attack does CVE-2008-2438 involve?
CVE-2008-2438 involves a remote attack that allows arbitrary code execution via a crafted command sent to TCP port 2954.
5
Is CVE-2008-2438 a buffer overflow vulnerability?
Yes, CVE-2008-2438 is a buffer overflow vulnerability caused by an integer overflow.