PT-2005-2792 · Hewlett Packard · Hp Radia Notify Daemon
John Cartwright
·
Published
2005-05-03
·
Updated
2011-03-08
·
CVE-2005-1825
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP Radia Notify Daemon versions 2.x through 4.x
HP Radia Notify Daemon version 3.1.2.0
Description
The issue is related to multiple stack-based buffer overflows in the
nvd exec function. This allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.Recommendations
For HP Radia Notify Daemon versions 2.x through 4.x, update to a version that fixes the buffer overflow issue in the
nvd exec function.
For HP Radia Notify Daemon version 3.1.2.0, update to a version that fixes the buffer overflow issue in the nvd exec function.
As a temporary workaround, consider restricting access to the RADEXECD process to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Radia Notify Daemon