Vulnerability Note VU#412228

Citrix Presentation Server heap based buffer overflow

Original Release date: 22 Jan 2008 | Last revised: 22 Jan 2008

Overview

A heap-based buffer overflow in Citrix Presentation Server may allow a remote attacker to execute arbitrary code on an vulnerable system in the context of the system user.

Description

Citrix Presentation Server is an application delivery system providing access to users accross a network. Presentation Server includes the Independent Management Architecture (IMA) service, which is responsible for the deployment of applications, policies, and other resources of remote hosts. The IMA service (ImaSrv.exe) listens by default on 2512/tcp or 2513/tcp. The service contains a boundary error which can be exploited by an attacker by sending a maliciously crafted packet to port 2512/tcp or 2513/tcp to initiate the buffer overflow.

Impact

By sending a maliciously crafted packet to port 2512/tcp or 2513/tcp, a remote attacker could execute arbitrary code on an vulnerable system in the context of the system user.

Solution

Apply the updates to this vulnerability as provided in Citrix Knowledge Center Article CTX114487.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
CitrixAffected-18 Jan 2008
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This vulnerability was discovered by Eric Detoisien and reported via TippingPoint/ZDI.

This document was written by Joseph W. Pruszynski.

Other Information

  • CVE IDs: Unknown
  • Date Public: 17 Jan 2008
  • Date First Published: 22 Jan 2008
  • Date Last Updated: 22 Jan 2008
  • Severity Metric: 4.33
  • Document Revision: 18

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.