Description
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_SCRIPT message.
Affected products
- HP / openview_storage_data_protector6.00 – 6.00
- HP / openview_storage_data_protector6.10 – 6.10
- HP / openview_storage_data_protector6.11 – 6.11
References
- MISChttp://www.securityfocus.com/bid/47638
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/67203
- VENDOR_ADVISORYhttp://zerodayinitiative.com/advisories/ZDI-11-146/
- MISChttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02810240
- MISChttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02810240
- VENDOR_ADVISORYhttp://secunia.com/advisories/44402
- MISChttp://www.securitytracker.com/id?1025454
- MISChttp://osvdb.org/72189
- MISChttp://www.securityfocus.com/archive/1/517767/100/0/threaded