Overview
HP LoadRunner contains a buffer overflow vulnerability when parsing Virtual User script files.
Description
According to HP's website: HP LoadRunner software is the industry standard for performance validation. It allows you to prevent application performance problems by detecting bottlenecks before a new system or upgrade is deployed. HP LoadRunner contains a buffer overflow vulnerability when parsing Virtual User script (.usr) files containing long strings for directives, causing the HP LoadRunner application to crash. |
Impact
An attacker could exploit the vulnerability by tricking a user into opening a crafted .usr file, causing HP LoadRunner to crash leading to possible execution of arbitrary code. |
Solution
HP has stated they are planning to release a patch to address this vulnerability. As of this writing the patch has not been released. |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&cp=1-11-126-17^8_4000_100__
Acknowledgements
Thanks to Jeremy Brown for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
| CVE IDs: | None |
| Severity Metric: | 0.34 |
| Date Public: | 2011-05-31 |
| Date First Published: | 2011-05-31 |
| Date Last Updated: | 2011-05-31 18:11 UTC |
| Document Revision: | 11 |