First published: Thu Jun 10 2010(Updated: )
Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1961 is considered a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2010-1961, upgrade to a patched version of HP OpenView Network Node Manager that addresses the buffer overflow issue.
CVE-2010-1961 affects HP OpenView Network Node Manager versions 7.51 and 7.53 on Solaris, Windows, HP-UX, and Linux.
Attackers can exploit CVE-2010-1961 to execute arbitrary code remotely on affected systems.
While upgrading to a secure version is recommended, temporarily restricting access to vulnerable components can act as a workaround for CVE-2010-1961.