CVE-2007-4349
The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service…
Does this matter?
Lower severity and a low EPSS score (3.08%). Track it; it rarely justifies an emergency change on its own.
Description
The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 3.08% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- hp/openview performance agent · hp/openview reporter · hp/performance agent · hp/reporter
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://marc.info/?l=bugtraq&m=122876677518654&w=2
- http://marc.info/?l=bugtraq&m=122876827120961&w=2
- http://secunia.com/advisories/27054Vendor Advisory
- http://secunia.com/secunia_research/2007-83/Vendor Advisory
- http://securityreason.com/securityalert/4501
- http://www.securityfocus.com/archive/1/497648/100/0/threaded
- http://www.securityfocus.com/bid/31860Patch
- http://www.securitytracker.com/id?1021092
- http://www.vupen.com/english/advisories/2008/2888Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46028
- http://marc.info/?l=bugtraq&m=122876677518654&w=2
- http://marc.info/?l=bugtraq&m=122876827120961&w=2
- http://secunia.com/advisories/27054Vendor Advisory
- http://secunia.com/secunia_research/2007-83/Vendor Advisory
- http://securityreason.com/securityalert/4501
- http://www.securityfocus.com/archive/1/497648/100/0/threaded
- http://www.securityfocus.com/bid/31860Patch
- http://www.securitytracker.com/id?1021092
- http://www.vupen.com/english/advisories/2008/2888Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46028
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.