Citrix Provisioning Services Unspecified Flaw Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1027004 |
|
SecurityTracker URL: http://securitytracker.com/id/1027004
|
|
CVE Reference:
CVE-2012-4068
(Links to External Site)
|
Updated: Jul 26 2012
|
Original Entry Date: May 2 2012
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 6.1 and prior
|
Description:
A vulnerability was reported in Citrix Provisioning Services. A remote user can execute arbitrary code on the target system.
A remote user can send a specially crafted packet to trigger an unspecified flaw and execute arbitrary code on the target system. The code will run with the privileges of the target service.
An anonymous researcher reported this vulnerability via iDefense.
|
Impact:
A remote user can execute arbitrary code on the target system.
|
Solution:
The vendor has issued a hotfix.
6.1:
http://support.citrix.com/article/CTX133149
6.0:
http://support.citrix.com/article/CTX133148
5.6 SP3:
http://support.citrix.com/article/CTX133187
The vendor's advisory is available at:
http://support.citrix.com/article/CTX133039
|
Vendor URL: support.citrix.com/article/CTX133039 (Links to External Site)
|
Cause:
Not specified
|
Underlying OS:
Windows (2003), Windows (2008)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 02 May 2012 18:36:34 +0000
Subject: Citrix Provisioning Services
|
http://support.citrix.com/article/CTX133039
|
|