vendor:
Data Protector Media Operations
by:
d0lc3
4,3
CVSS
MEDIUM
Integer Overflow
190
CWE
Product Name: Data Protector Media Operations
Affected Version From: 6.11
Affected Version To: 6.11
Patch Exists: Yes
Related CWE: N/A
CPE: a:hewlett_packard:data_protector_media_operations:6.11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Spa
2010
HP Data Protector Media Operations 6.11 HTTP Server Remote Integer Overflow DoS
HP Data Protector Media Operations has an embedded HTTP server, allowing access through this protocol for users. A flaw was detected on this implementation, causing remote and pre-authenticated DoS: Integer Overflow handling string sent length through POST method. Integer Overflow causes unexpected variable initiation (reset to 0) followed by its dereferenciation (Null Dereference), crashing server and thus denying service to legitimate users.
Mitigation:
Update to the latest version of HP Data Protector Media Operations.