HP Data Protector Express Buffer Overflow

Strike ID:
E10-5bj01
CVSS:
7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2010

Description

This strike exploits a vulnerability in HP DataProtector Express. The vulnerability exists in how the DtbClsLogin method hanles the username parameter. A 240 byte stack buffer is allocated for this parameter, and because it is not validated properly a large value will overflow the stack buffer.

CVE

Bid