Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://www.irmplc.com/index.php/111-Vendor-Alerts | |
http://www.securityfocus.com/archive/1/482353/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/26092 | vdb entry |
http://osvdb.org/45276 | vdb entry |
http://securityreason.com/securityalert/3249 | third party advisory |