HP OpenView Storage Data Protector Code Execution Vulnerabilities
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been identified in HP OpenView Storage Data Protector, which could be exploited by remote attackers to gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by buffer overflows and directory traversal errors in the Backup Client Service (OmniInet.exe) when processing user-supplied packets, which could be exploited by remote unauthenticated attackers to view or download arbitrary files on a vulnerable system or execute arbitrary code with SYSTEM privileges.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- HP OpenView Storage Data Protector version 6.00 (Windows)
- HP OpenView Storage Data Protector version 6.10 (Windows)
- HP OpenView Storage Data Protector version 6.11 (Windows)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to version A.06.20 or subsequent :
http://hp.com/go/dataprotector
Vulnerability Identifier
- CVE-2011-0921
- CVE-2011-0922
- CVE-2011-0923
- CVE-2011-0924
- CVE-2011-1728
- CVE-2011-1729
- CVE-2011-1730
- CVE-2011-1731
- CVE-2011-1732
- CVE-2011-1733
- CVE-2011-1734
- CVE-2011-1735
- CVE-2011-1736
Source
Related Link
Share with