CVE Vulnerabilities

CVE-2008-1842

Published: Apr 16, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Openview_network_node_managerHp*7.53 (including)
Openview_network_node_managerHp4.11 (including)4.11 (including)
Openview_network_node_managerHp5.0.1 (including)5.0.1 (including)
Openview_network_node_managerHp5.01 (including)5.01 (including)
Openview_network_node_managerHp6.0.1 (including)6.0.1 (including)
Openview_network_node_managerHp6.1 (including)6.1 (including)
Openview_network_node_managerHp6.2 (including)6.2 (including)
Openview_network_node_managerHp6.4 (including)6.4 (including)
Openview_network_node_managerHp6.10 (including)6.10 (including)
Openview_network_node_managerHp6.20 (including)6.20 (including)
Openview_network_node_managerHp6.31 (including)6.31 (including)
Openview_network_node_managerHp6.41 (including)6.41 (including)
Openview_network_node_managerHp7.0.1 (including)7.0.1 (including)
Openview_network_node_managerHp7.01 (including)7.01 (including)
Openview_network_node_managerHp7.50 (including)7.50 (including)
Openview_network_node_managerHp7.51 (including)7.51 (including)
Openview_network_node_managerHp8.01 (including)8.01 (including)

References