First published: Tue Apr 28 2009(Updated: )
Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.01 | |
HP OpenView Network Node Manager | =7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2438 is a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2008-2438, upgrade your HP OpenView Network Node Manager to a patched version that addresses this vulnerability.
CVE-2008-2438 affects HP OpenView Network Node Manager versions 7.01, 7.51, and 7.53.
CVE-2008-2438 involves a remote attack that allows arbitrary code execution via a crafted command sent to TCP port 2954.
Yes, CVE-2008-2438 is a buffer overflow vulnerability caused by an integer overflow.