Vulnerability Description
The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Openview Performance Agent | c.04.60 |
| Hp | Openview Reporter | 3.70 |
| Hp | Performance Agent | 4.70 |
| Hp | Reporter | 3.8 |
References
- http://marc.info/?l=bugtraq&m=122876677518654&w=2
- http://marc.info/?l=bugtraq&m=122876827120961&w=2
- http://secunia.com/advisories/27054Vendor Advisory
- http://secunia.com/secunia_research/2007-83/Vendor Advisory
- http://securityreason.com/securityalert/4501
- http://www.securityfocus.com/archive/1/497648/100/0/threaded
- http://www.securityfocus.com/bid/31860Patch
- http://www.securitytracker.com/id?1021092
- http://www.vupen.com/english/advisories/2008/2888Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46028
- http://marc.info/?l=bugtraq&m=122876677518654&w=2
- http://marc.info/?l=bugtraq&m=122876827120961&w=2
- http://secunia.com/advisories/27054Vendor Advisory
- http://secunia.com/secunia_research/2007-83/Vendor Advisory
- http://securityreason.com/securityalert/4501
FAQ
What is CVE-2007-4349?
CVE-2007-4349 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) al...
How severe is CVE-2007-4349?
CVE-2007-4349 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4349?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Openview Performance Agent, Hp Openview Reporter, Hp Performance Agent, Hp Reporter.