CVE-2008-0356
Summary
| CVE | CVE-2008-0356 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-18 22:00:00 UTC |
| Updated | 2018-10-15 21:59:00 UTC |
| Description | Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Access Essentials | All | All | All | All |
| Application | Citrix | Desktop Server | 1.0 | All | All | All |
| Application | Citrix | Desktop Server | 1.0 | All | All | All |
| Application | Citrix | Metaframe Presentation Server | All | All | All | All |
| Application | Citrix | Presentation Server | All | All | All | All |
| Application | Citrix | Presentation Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Citrix Presentation Server IMA Service Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| Zero Day Initiative | MISC | zerodayinitiative.com | |
| Citrix Presentation Server IMA Service Buffer Overflow Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Citrix Presentation Server Buffer Overflow in IMA Service Lets Remote Users Execute Arbitrary Code | SECTRACK | www.securitytracker.com | |
| CTX114487 - Vulnerability in Presentation Server's IMA Service could result in arbitrary code execution. - Citrix Knowledge Center | CONFIRM | support.citrix.com | Patch |
| US-CERT Vulnerability Note VU#412228 | CERT-VN | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.