Board logo

标题: HP OpenView Products Shared Trace Service缓冲溢出 [打印本页]

作者: pioneer     时间: 2007-8-13 14:45    标题: HP OpenView Products Shared Trace Service缓冲溢出

软件名

HP OpenView Performance Insight (OVPI) 5.x

HP OpenView Dashboard 2.x

HP OpenView Business Process Insight (OVBPI) 1.x

HP OpenView Business Process Insight (OVBPI) 2.x

HP OpenView Service Desk Process Insight (SDPI) 1.x

HP OpenView Service Desk Process Insight (SDPI) 2.x

HP Business Process Insight (HPBPI) 1.x

HP Business Process Insight (HPBPI) 2.x

HP Service Desk Process Insight (HPSDPI) 1.x

HP Service Desk Process Insight (HPSDPI) 2.x

HP OpenView Network Node Manager (NNM) 6.x

HP OpenView Network Node Manager (NNM) 7.x

HP OpenView Service Quality Manager (OV SQM) 1.x

HP OpenView Operations Manager for Windows (OVOW) 7.x

HP OpenView Operations HTTPS Agent 8.x

HP OpenView Reporter 3.x

HP OpenView Performance Agent

HP OpenView Performance Manager (OVPM) 5.x

HP OpenView Performance Manager (OVPM) 6.x

HP OpenView Internet Service (OVIS) 6.x

来源

secunia.com/

描述

这可被恶意用来危害有漏洞的系统,
Shared Trace Service组件在处理特定请求时的越界错误,这可通过发送一个特定请求到服务来导致基址缓冲溢出。这个漏洞影响了以下产品及版本
* HP OpenView Internet Service (OVIS) v6.00, v6.10, v6.11 (Japanese),
v6.20 running HP OpenView Cross Platform Component (XPL) vB.60.81.00,
vB.60.90.00,和vB.61.90.000
* HP OpenView Performance Manager (OVPM) 5.x和6.x
* HP OpenView Performance Agent (OVPA) 4.5和4.6
* HP OpenView Reporter 3.7
* HP OpenView Operations (OVO) Agents OVO8.x HTTPS agents
* HP OpenView Operations Manager for Windows (OVOW) v7.5 with the
OpenView Operations (OVO) add on module for OpenView
Operations-Business Availability Center (OVO-BAC)
* HP OpenView Quality Manager (OV SQM) v1.2 SP1, v1.3, v1.40 running
HP OpenView Cross Platform Component (XPL) 2.60.041, 2.61.060 和
2.61.110
* HP OpenView Network Node Manager (OV NNM) v6.41, v7.01, v7.50
running XPL earlier than 03.10.040
* HP OpenView Business Process Insight (OVBPI), HP Business Process
Insight (HPBPI) , HP OpenView Service Desk Process Insight (SDPI),
和 HP Service Desk Process Insight (HPSDPI) versions 1.0, 1.1x, 2.0x
和2.10x
* HP OpenView Dashboard v2.01 running HP OpenView Cross Platform
Component (XPL) vB.60.90.00和vB.61.90.000
* HP OpenView Performance Insight (OVPI) v5.0, v5.1, v5.1.1, v5.1.2,
v5.2 running HP OpenView Cross Platform Component (XPL) earlier than
v3.10.040

解决方案

应用补丁,参照厂商建议细节




欢迎光临 微点交流论坛 (http://bbs.micropoint.com.cn/) bbs.micropoint.com.cn