First published: Wed Jan 16 2008(Updated: )
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO SmartSockets RTserver | <=6.8.0 | |
Tibco Rtworks | <=4.0.3 | |
Tibco Ems Server | ||
TIBCO Enterprise Message Service |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5657 has a high severity rating due to its potential for remote code execution.
To fix CVE-2007-5657, you should upgrade TIBCO SmartSockets RTserver to version 6.9.0 or later, RTworks to 4.0.4 or later, and EMS to 4.4.2 or later.
CVE-2007-5657 affects TIBCO SmartSockets RTserver versions up to 6.8.0, RTworks versions before 4.0.4, and EMS versions from 4.0.0 to 4.4.1.
CVE-2007-5657 can be exploited by remote attackers who send crafted requests to the vulnerable services.
The components affected by CVE-2007-5657 include TIBCO SmartSockets RTserver, RTworks, and certain versions of TIBCO Enterprise Message Service.