HTTP: HP Device Access Manager for HP ProtectTools Heap Memory Corruption

This signature detects attempts to use unsafe ActiveX controls in the HP Device Access Manager for HP ProtectTools. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

HP Device Access Manager for HP ProtectTools is prone to a remote heap-memory-corruption vulnerability. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. HP Device Access Manager for HP ProtectTools versions prior to 6.1.0.1 are vulnerable.

Affected Products

Hp device_access_manager_for_hp_protecttools

References

BugTraq: 50895

CVE: CVE-2011-4162

Short Name
HTTP:STC:ACTIVEX:HP-PROTECT-DAM
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access CVE-2011-4162 Corruption Device HP Heap Manager Memory ProtectTools bid:50895 for
Release Date
12/13/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Hp

CVSS Score

7.5

Found a potential security threat?