9.8

CVE-2016-4359

Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Loadrunner Version 11.52 Update p3
Hp ≫ Loadrunner Version 12.00 Update p1
Hp ≫ Loadrunner Version 12.01 Update p3
Hp ≫ Loadrunner Version 12.02 Update p2
Hp ≫ Loadrunner Version 12.50 Update p1
Hp ≫ Performance Center Version 11.52 Update p3
Hp ≫ Performance Center Version 12.00 Update p1
Hp ≫ Performance Center Version 12.01 Update p3
Hp ≫ Performance Center Version 12.20 Update p2
Hp ≫ Performance Center Version 12.50 Update p1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.77% 0.964
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securityfocus.com/bid/90975
http://www.securitytracker.com/id/1036006
Third Party Advisory
VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-16-363
Third Party Advisory
VDB Entry
https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423
Vendor Advisory
https://www.tenable.com/security/research/tra-2016-16