First published: Thu Dec 10 2009(Updated: )
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4178 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2009-4178, users should update HP OpenView Network Node Manager to the latest version available from HP.
CVE-2009-4178 affects HP OpenView Network Node Manager versions 7.0.1, 7.51, and 7.53 on various platforms including Windows, Solaris, and Linux.
Yes, CVE-2009-4178 can be exploited remotely due to a vulnerability in the Topic parameter.
Exploitation of CVE-2009-4178 could allow an attacker to execute arbitrary code on the affected system.