Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in the sel parameter.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=127360750704351&w=2 | vendor advisory |
http://www.securityfocus.com/archive/1/511245/100/0/threaded | mailing list |
http://zerodayinitiative.com/advisories/ZDI-10-081/ |