CVE-2011-4791

HP Data Protector Media Operations < 6.11 - Remote Code Execution via Length Field Overflow

Title source: llm
STIX 2.1

Description

DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/521472
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-11-112/

Scores

EPSS 0.1683
EPSS Percentile 95.0%

Details

CWE
CWE-94
Status published
Products (5)
hp/data_protector_media_operations 5.0
hp/data_protector_media_operations 5.1
hp/data_protector_media_operations 5.5
hp/data_protector_media_operations 6.10
hp/data_protector_media_operations < 6.11
Published Feb 03, 2012
Tracked Since Feb 18, 2026