Risk: Medium
Vulnerabilities have been found in various HP OpenView programs, which can enable malicious users to compromise a vulnerable system.
The vulnerabilities are caused due to boundary errors in the Shared Trace Service component within ovtrcsvc.exe and OVTrace.exe when handling certain requests. These can be exploited to cause stack-based buffer overflows by sending specially crafted requests (opcode handler 0x1a or 0x0f) to the service.
HP has issued multiple advisories for the vulnerabilities, which are available at:
http://secunia.com/advisories/26394/