In association with heise online

20 November 2007, 10:31

Citrix remedies a vulnerability in several products

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Citrix has released a number of updates intended to make attacking Citrix servers more difficult. According to a security advisory it may be possible to execute application-related commands on a server using prepared ICA files with the attacked user's rights. To do this, however, the user has to open this type of file or load it with the ICA browser plug-in. In the latter case, all that is required is a visit to a website. In order to launch a successful attack, the victim has to have the right to execute so-called "published applications". Also, the Citrix server has to be configured to forward additional parameters to the application.

The following software is affected:

Access Essentials 1.0
Citrix Access Essentials 1.5
Citrix Access Essentials 2.0
Citrix MetaFrame Presentation Server 3.0 for Microsoft Windows 2000
Citrix MetaFrame Presentation Server 3.0 for Microsoft Windows 2003
Citrix Presentation Server 4.0 for Microsoft Windows 2000
Citrix Presentation Server 4.0 for Microsoft Windows 2003
Citrix Presentation Server 4.0 x64 Edition
Citrix Presentation Server 4.5 for Windows Server 2003
Citrix Presentation Server 4.5 for Windows Server 2003 Feature Pack 1
Citrix Presentation Server 4.5 for Windows Server 2003 x64 Edition

See also:

(mba)

Print Version | Send by email | Permalink: http://h-online.com/-734006
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit