HP Openview Data Protector Cell Manager Integer Overflow

Strike ID:
E07-4rd01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2007

Description

This strike identifies an integer overflow in HP OpenView Data Protector Cell Manager. This vulnearbility is due to the way the Length parameter is processed. If this parameter is greater than 0xFFFFFFF8, length which is used in the calculation of a size parameter for a heap buffer causes an integer overflow. When data is copied to this undersized buffer, critical memory is overwritten.

CVE

Bid