TIBCO SmartSockets Request Heap Buffer Overflow Vulnerability
BID:27294
Info
TIBCO SmartSockets Request Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 27294 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5658 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2008 12:00AM |
| Updated: | Jan 16 2008 04:28PM |
| Credit: | McSlibin and Sean Larsson of VeriSign iDefense Labs are credited with discovering this issue. |
| Vulnerable: |
TIBCO SmartSockets Product Family (RTworks) 4.0.3 TIBCO SmartSockets 6.8 TIBCO Enterprise Message Service (EMS) 4.4.1 TIBCO Enterprise Message Service (EMS) 4.0 |
| Not Vulnerable: |
TIBCO SmartSockets Product Family (RTworks) 4.0.4 TIBCO SmartSockets 6.8.1 TIBCO Enterprise Message Service (EMS) 4.4.2 |
Discussion
TIBCO SmartSockets Request Heap Buffer Overflow Vulnerability
TIBCO SmartSockets is prone to a heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the affected application, denying service to legitimate users.
The following components are affected:
TIBCO RTworks Server (rtserver)
TIBCO RTworks Data Archive Process (rtarchive)
TIBCO RTworks Data Playback Process (rtplayback)
TIBCO RTworks Data Acquisi- TIon Process (rtdaq)
TIBCO RTworks Human Computer Interface (rthci)
TIBCO RTworks Inference Engine (r- TIe)
TIBCO RTworks libraries (r- TIpc, rtu- TIl)
TIBCO SmartSockets is prone to a heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the affected application, denying service to legitimate users.
The following components are affected:
TIBCO RTworks Server (rtserver)
TIBCO RTworks Data Archive Process (rtarchive)
TIBCO RTworks Data Playback Process (rtplayback)
TIBCO RTworks Data Acquisi- TIon Process (rtdaq)
TIBCO RTworks Human Computer Interface (rthci)
TIBCO RTworks Inference Engine (r- TIe)
TIBCO RTworks libraries (r- TIpc, rtu- TIl)
Exploit / POC
TIBCO SmartSockets Request Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
TIBCO SmartSockets Request Heap Buffer Overflow Vulnerability
Solution:
The vendor released updates and an advisory to address this issue. Please see the references for more information.
Solution:
The vendor released updates and an advisory to address this issue. Please see the references for more information.
References
TIBCO SmartSockets Request Heap Buffer Overflow Vulnerability
References:
References:
- TIBCO Enterprise Message Service Vulnerabiltiy (TIBCO)
- TIBCO SmartSockets Homepage (TIBCO)
- TIBCO SmartSockets RTserver Heap Overflow Vulnerability (iDefense Labs)
- iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver (iDefense Labs
) - TIBCO SmartSockets Product Family (RTworks) vulnerability (TIBCO)
- TIBCO SmartSockets Vulnerability (TIBCO)