CVE-2011-4791: Code Injection
Published Feb 3, 2012
·Updated
DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field.
Affected Software
5 affected components
HP Data Protector Media Operations=5.1
HP Data Protector Media Operations=5.0
HP Data Protector Media Operations=5.5
HP Data Protector Media Operations<=6.11
HP Data Protector Media Operations=6.10
Event History
Feb 3, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4791?
CVE-2011-4791 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2011-4791?
To fix CVE-2011-4791, you should update HP Data Protector to version 6.12 or later.
3
Who is affected by CVE-2011-4791?
CVE-2011-4791 affects HP Data Protector Media Operations versions up to 6.11.
4
What type of vulnerability is CVE-2011-4791?
CVE-2011-4791 is a remote code execution vulnerability.
5
Can CVE-2011-4791 be exploited remotely?
Yes, CVE-2011-4791 can be exploited remotely by attackers sending specially crafted requests.