106 lines
3.2 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2007-2280",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-12-18T19:30:00.203",
"lastModified": "2009-12-23T06:26:09.640",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844."
},
{
"lang": "es",
"value": "Desbordamiento de pila basado en b\u00fafer en OmniInet.exe (demonio del servicio del cliente backup) en el componente de administraci\u00f3n de recuperaci\u00f3n de aplicaciones en HP OpenView Storage Data Protector v5.50 y v6.0 permite a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de un comando MSG_PROTOCOL con argumentos demasiado largos. Se trata de una vulnerabilidad diferente a CVE-2009-3844."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hp:openview_storage_data_protector:5.50:*:*:*:*:*:*:*",
"matchCriteriaId": "C114C6E6-0995-4449-BEBA-3247B88D8CFC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hp:openview_storage_data_protector:6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2924E972-C490-4359-8E85-C5A4BDE088C4"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=126106261622540&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1023361",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/bid/37396",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/3594",
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-09-099/",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
}
]
}