vendor:
HP Data Protector Manager
by:
Roi Mallo, Pepelux
7.5
CVSS
HIGH
Remote Denial of Service Vulnerabilities
772
CWE
Product Name: HP Data Protector Manager
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2, Windows XP SP3
2011
HP Data Protector Manager v6.11
The vulnerability allows remote attackers to cause a denial of service (DoS) condition on the target system. By sending a specially crafted packet to the RDS service, the program exits due to memory allocation failure. The vulnerability is caused by a flaw in the _ncp32.dll and _rm32.dll files. The _ncp32.dll file receives the packet and uses the _rm32.dll file to allocate memory. However, when the packet size is too big, the malloc function fails to allocate the required memory, causing the program to exit. This vulnerability has been tested on Windows XP SP2 and Windows XP SP3.
Mitigation:
No official patch or mitigation is available for this vulnerability.