|
|
|
![]() |
Vulnerability Note VU#303012HP Mercury products vulnerable to buffer overflowOverviewSome HP Mercury products are vulnerable to a buffer overflow and may allow an attacker to execute arbitrary code.I. DescriptionThe magentproc.exe service provided with some HP Mercury products fails to properly parse values in the server_ip_name field. If an overly long value is sent in this parameter, a stack-based buffer overflow may be triggered within the mchan.dll library. An attacker may be able to exploit this vulnerability by sending a specially crafted packet to the agent (port 54345/tcp). HP reports that the following products are affected by this issue:
II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code.III. SolutionApply an Update
References
This vulnerability was reported in HP Security Document ID #c00854250. This issue was discovered by Eric Detoisien and reported via Zero Day Initiative. This document was written by Katie Steiner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||