Login: Password: Forget password? / Register New User 
logo
Home Home | Current issue Current issue | Forum and Community Forum & Community | Onekit's Software OneKit's Software | About us About us | Live Chat with Support Team Chat with support []
Games Graphics & Design MP3 & Audio Internet & Networks System & Utilities Home & Education Business WebDev SoftDev
Reviews & Articles :: Citrix vulnerability found
Issue: March 2007 > System & Utilities > Article "Citrix vulnerability found"

Citrix vulnerability found (Citrix vulnerability found)  Citrix vulnerability found

System & Utilities
Advertisement on Onekit.com Software Magazine
A vulnerability has been found in Citrix's Presentation Server Client, an application that allows remote users to access corporate servers from outside the office.

Versions older than 10.0 could be vulnerable to a buffer overflow which would enable an attacker to compromise a user's machine, according to researcher Karl Lynn of Juniper Networks, who discovered the vulnerability. Security advisory organisation Secunia has rated the vulnerability as highly critical in a security advisory.

The vulnerability is caused by an error in the support for ICA connections through a proxy server. This may be exploited to execute arbitrary code when a user visits a malicious web site, Citrix warned in an advisory.

ICA (Independent Computing Architecture), designed by Citrix, is a proprietary protocol for application server systems. The protocol gives specifications for passing data between servers and clients, regardless of platform.

The vulnerability currently has no patch, and Citrix recommends users protect themselves by upgrading to version 10.0 of Citrix Presentation Server Client.

Related Links:
March 3, 2007
Author: Tom Espiner
There are no users' comments | Post your comment
Copyright 2003-2008 - Software Magazine, onekit.com, Legal Notices
Advertisement Advertisement