Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

TIBCO Hawk Configuration Interface Local Buffer Overflow Vulnerability

TIBCO Hawk is susceptible to a local buffer-overflow vulnerability. This issue is due to the application's failure to properly check boundaries of user-supplied command-line argument data before copying it to an insufficiently sized memory buffer.

Attackers may exploit this issue to execute arbitrary machine code with elevated privileges. This is a vulnerability only if the affected software is installed with setuid-privileges on UNIX computers or if it is installed as a service running with administrative privileges on Microsoft Windows computers.

TIBCO Hawk versions prior to 4.6.1 and TIBCO Runtime Agent versions prior to 5.4 are vulnerable to this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus