Overview
HP LoadRunner contains a buffer overflow vulnerability when parsing Virtual User script files.
Description
According to HP's website: HP LoadRunner software is the industry standard for performance validation. It allows you to prevent application performance problems by detecting bottlenecks before a new system or upgrade is deployed. HP LoadRunner contains a buffer overflow vulnerability when parsing Virtual User script (.usr) files containing long strings for directives, causing the HP LoadRunner application to crash. |
Impact
An attacker could exploit the vulnerability by tricking a user into opening a crafted .usr file, causing HP LoadRunner to crash leading to possible execution of arbitrary code. |
Solution
HP has stated they are planning to release a patch to address this vulnerability. As of this writing the patch has not been released. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&cp=1-11-126-17^8_4000_100__
Acknowledgements
Thanks to Jeremy Brown for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | None |
Severity Metric: | 0.34 |
Date Public: | 2011-05-31 |
Date First Published: | 2011-05-31 |
Date Last Updated: | 2011-05-31 18:11 UTC |
Document Revision: | 11 |