PT-2009-3825 · Tibco · Tibco Enterprise Message Service+2
Publicado
2009-04-30
·
Atualizado
2017-08-17
·
CVE-2009-1291
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO SmartSockets versions prior to 6.8.2
TIBCO SmartSockets Product Family (aka RTworks) versions prior to 4.0.5
TIBCO Enterprise Message Service (EMS) versions 4.0.0 through 5.1.1
Description
The issue allows remote attackers to execute arbitrary code via inbound data. This can be demonstrated by requests to the UDP interface of the RTserver component and data injection into the TCP stream to tibemsd.
Recommendations
For TIBCO SmartSockets versions prior to 6.8.2, update to version 6.8.2 or later.
For TIBCO SmartSockets Product Family (aka RTworks) versions prior to 4.0.5, update to version 4.0.5 or later.
For TIBCO Enterprise Message Service (EMS) versions 4.0.0 through 5.1.1, update to a version outside of this range.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tibco Enterprise Message Service
Tibco Smartsockets
Tibco Smartsockets Product Family