SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  MetaFrame Presentation Server Vendors:  Citrix
Citrix WinCE MetaFrame Presentation Server Client Stack Overflow Lets Remote Users Execute Arbitrary Code and Another Bug Lets Remote Users Create Arbitrary Shortcuts
SecurityTracker Alert ID:  1013815
SecurityTracker URL:  http://securitytracker.com/id?1013815
CVE Reference:  CAN-2004-1077 ,  CAN-2004-1078   (Links to External Site)
Date:  Apr 26 2005
Impact:  Execution of arbitrary code via network, Modification of system information, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): prior to 8.33; Client for WinCE
Description:  Two vulnerabilities were reported in the Citrix MetaFrame Presentation Server client for WinCE. A remote user can execute arbitrary code on the target system.

A remote user that can cause the Program Neighborhood Agent to be explicitly configured to point to a malicious server can trigger a stack overflow in the Program Neighborhood Agent [CVE: CAN-2004-1078]. A remote user can also cause arbitrary shortcuts to be created on the target user's system [CVE: CAN-2004-1077].

The Citrix MetaFrame Presentation Server client for WinCE is affected.

WinCE client versions that do not include the Program Neighborhood Agent are not affected.

The vendor credits iDEFENSE with reporting these vulnerabilities.

Impact:  A remote user can execute arbitrary code on the target user's system.

A remote user can create arbitrary shortcuts on the target user's system.

Solution:  The vendor has issued a fixed version (8.33), available at:

http://www.citrix.com/English/SS/downloads/downloads.asp?dID=2755

Vendor URL:  support.citrix.com/kb/entry.jspa?entryID=6156&categoryID=149 (Links to External Site)
Cause:  Access control error, Boundary error
Underlying OS:  Windows (CE)
Underlying OS Comments:  Client for WinCE

Message History:   None.


 Source Message Contents


 

[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2005, SecurityGlobal.net LLC