Short Name |
APP:HPOV:HP-DPBC-OF |
|---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Data Protector Backup Client Service GET_FILE |
Release Date |
2011/06/20 |
Update Number |
1942 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
A code execution vulnerability exists in HP Data Protector Backup Client Service. The vulnerability is due to a buffer overflow in the processing of GET_FILE messages. Remote unauthenticated attackers could exploit this vulnerability by sending a crafted request to the target service. Successful exploitation would allow attackers to execute arbitrary code with the privileges of the affected service which runs under the SYSTEM user on the Windows platforms.
HP OpenView Storage Data Protector is prone to multiple buffer-overflow vulnerabilities and an information-disclosure vulnerability. An attacker can exploit these issues to execute arbitrary code with SYSTEM-level privileges and obtain potentially sensitive information. Successful exploits will completely compromise an affected computer.