Vulnerability CVE-2007-3872


Published: 2007-08-09   Modified: 2012-02-12

Description:
Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
HP -> Openview operations 
HP -> Shared trace service 

 References:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=574
http://www.vupen.com/english/advisories/2007/2841
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109171
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109171
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01106515
http://xforce.iss.net/xforce/xfdb/35928
http://www.securitytracker.com/id?1018548
http://www.securityfocus.com/bid/25255
http://secunia.com/advisories/26394
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01115068
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01114156
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01114023
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01112038
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01111851
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01110627
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01110576
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109617
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109584

Copyright 2024, cxsecurity.com

 

Back to Top