First published: Fri Aug 03 2007(Updated: )
rvd in TIBCO Rendezvous (RV) 7.5.2, when -no-lead-wc is omitted, might allow remote attackers to cause a denial of service (network instability) via a subject name with a leading (1) '*' (asterisk) or (2) '>' (greater than) wildcard character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Rendezvous | =7.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4161 is categorized as a denial of service vulnerability.
To mitigate CVE-2007-4161, ensure you use the -no-lead-wc option in TIBCO Rendezvous configuration.
CVE-2007-4161 affects TIBCO Rendezvous version 7.5.2.
CVE-2007-4161 allows remote attackers to induce network instability through specific wildcard characters in subject names.
Yes, CVE-2007-4161 can lead to denial of service, affecting system availability.