In association with heise online

12 November 2006, 22:55

Critical holes in products from Citrix

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Citrix has released an update to close two holes in several of its products. The problems are based on flaws in the IMA service (Independent Management Architecture) for network communication between various systems and management services. Hence a rigged packet to the IMA server on the TCP port 2512 or 2513 could lead to a heap overflow in an authentication module (ImaSystem.dll). That in turn could be used to plant code into a vulnerable system and then execute it with the service's rights, claims a flaw advisory from the Zero Day Initiative. No prior authentication is required for an attack. Packets with invalid name lengths can lead to a crash in the IMA process.

The error is present in all versions of Citrix MetaFrame XP and Presentation Server up to and including 4.0. This encompasses:

  • Citrix MetaFrame XP 1.0 for Windows 2000 Server
  • Citrix MetaFrame XP 1.0 for Windows Server 2003
  • Citrix MetaFrame Presentation Server 3.0 for Windows 2000 Server
  • Citrix MetaFrame Presentation Server 3.0 for Windows Server 2003
  • Citrix Presentation Server 4.0 for Windows 2000 Server
  • Citrix Presentation Server 4.0 for Windows Server 2003
  • Citrix Presentation Server 4.0 for Windows Server 2003 x64 Editions

See also:

(ehe)

Print Version | Send by email | Permalink: http://h-online.com/-731791
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit