HP StorageWorks File Migration Agent is prone to an overflow condition when parsing CIFS archive names and the root path of FTP archives. The HsmCfgSvc.exe service fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted packet, a remote attacker can potentially execute arbitrary code. |