TIBCO SmartSockets Multiple Pointer Offset Remote Code Execution Vulnerabilities
BID:27295
Info
TIBCO SmartSockets Multiple Pointer Offset Remote Code Execution Vulnerabilities
| Bugtraq ID: | 27295 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5657 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2008 12:00AM |
| Updated: | Jan 16 2008 04:38PM |
| Credit: | McSlibin and Sean Larsson of VeriSign iDefense Labs discovered these issues. |
| Vulnerable: |
TIBCO SmartSockets Product Family (RTworks) 4.0.3 TIBCO SmartSockets 6.8 |
| Not Vulnerable: |
TIBCO SmartSockets Product Family (RTworks) 4.0.4 TIBCO SmartSockets 6.8.1 |
Discussion
TIBCO SmartSockets Multiple Pointer Offset Remote Code Execution Vulnerabilities
TIBCO SmartSockets is prone to multiple remote code-execution vulnerabilities because user-supplied input is used to change valid pointer values.
Attackers can leverage these issues to execute arbitrary code with the privileges of the application. If the application is installed as a system service on Windows platforms, then the code will execute with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
SmartSockets 6.8.0 is vulnerable; other versions may also be affected.
The following components are affected:
TIBCO RTworks Server (rtserver)
TIBCO RTworks Data Archive Process (rtarchive)
TIBCO RTworks Data Playback Process (rtplayback)
TIBCO RTworks Data Acquisition Process (rtdaq)
TIBCO RTworks Human Computer Interface (rthci)
TIBCO RTworks Inference Engine (rtie)
TIBCO RTworks libraries (rtipc, rtutil)
TIBCO SmartSockets is prone to multiple remote code-execution vulnerabilities because user-supplied input is used to change valid pointer values.
Attackers can leverage these issues to execute arbitrary code with the privileges of the application. If the application is installed as a system service on Windows platforms, then the code will execute with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
SmartSockets 6.8.0 is vulnerable; other versions may also be affected.
The following components are affected:
TIBCO RTworks Server (rtserver)
TIBCO RTworks Data Archive Process (rtarchive)
TIBCO RTworks Data Playback Process (rtplayback)
TIBCO RTworks Data Acquisition Process (rtdaq)
TIBCO RTworks Human Computer Interface (rthci)
TIBCO RTworks Inference Engine (rtie)
TIBCO RTworks libraries (rtipc, rtutil)
Exploit / POC
TIBCO SmartSockets Multiple Pointer Offset Remote Code Execution Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
TIBCO SmartSockets Multiple Pointer Offset Remote Code Execution Vulnerabilities
Solution:
The vendor released advisories and fixes to address these issues. Please see the references for more information.
Solution:
The vendor released advisories and fixes to address these issues. Please see the references for more information.
References
TIBCO SmartSockets Multiple Pointer Offset Remote Code Execution Vulnerabilities
References:
References: