Multiple Citrix Products Session Reliability Server Security Bypass Vulnerability
BID:24116
Info
Multiple Citrix Products Session Reliability Server Security Bypass Vulnerability
| Bugtraq ID: | 24116 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2007 12:00AM |
| Updated: | May 23 2007 10:47PM |
| Credit: | Andrew Christensen of FortConsult is credited with the discovery of this issue. |
| Vulnerable: |
Citrix Presentation Server 4.0 Citrix MetaFrame Presentation Server 3.0 Citrix Access Essentials 1.5 Citrix Access Essentials 1.0 |
| Not Vulnerable: | |
Discussion
Multiple Citrix Products Session Reliability Server Security Bypass Vulnerability
Multiple Citrix products are prone to a security-bypass vulnerability because they fail to adequately enforce network-security policies.
An attacker can exploit this issue to gain unauthorized access to otherwise restricted ports on a vulnerable computer.
NOTE: This issue affects only Citrix products that have Session Reliability enabled.
Multiple Citrix products are prone to a security-bypass vulnerability because they fail to adequately enforce network-security policies.
An attacker can exploit this issue to gain unauthorized access to otherwise restricted ports on a vulnerable computer.
NOTE: This issue affects only Citrix products that have Session Reliability enabled.
Exploit / POC
Multiple Citrix Products Session Reliability Server Security Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Multiple Citrix Products Session Reliability Server Security Bypass Vulnerability
Solution:
Citrix has released an advisory and hotfixes to address this issue. Please see the references for more information.
Citrix Access Essentials 1.5
Citrix Access Essentials 1.0
Citrix MetaFrame Presentation Server 3.0
Solution:
Citrix has released an advisory and hotfixes to address this issue. Please see the references for more information.
Citrix Access Essentials 1.5
-
Citrix PSE400R03W2K3024.msp
http://support.citrix.com/servlet/KbServlet/download/13435-102-16726/P SE400R03W2K3024.msp -
Citrix PSF400R03W2K3024.msp
French
http://support.citrix.com/servlet/KbServlet/download/13438-102-16729/P SF400R03W2K3024.msp -
Citrix PSG400R03W2K3024.msp
German
http://support.citrix.com/servlet/KbServlet/download/13436-102-16727/P SG400R03W2K3024.msp -
Citrix PSJ400R03W2K3024.msp
Japanese
http://support.citrix.com/servlet/KbServlet/download/13439-102-16730/P SJ400R03W2K3024.msp -
Citrix PSS400R03W2K3024.msp
Spanish
http://support.citrix.com/servlet/KbServlet/download/13437-102-16728/P SS400R03W2K3024.msp
Citrix Access Essentials 1.0
-
Citrix PSE400R03W2K3024.msp
http://support.citrix.com/servlet/KbServlet/download/13435-102-16726/P SE400R03W2K3024.msp -
Citrix PSF400R03W2K3024.msp
French
http://support.citrix.com/servlet/KbServlet/download/13438-102-16729/P SF400R03W2K3024.msp -
Citrix PSG400R03W2K3024.msp
German
http://support.citrix.com/servlet/KbServlet/download/13436-102-16727/P SG400R03W2K3024.msp -
Citrix PSJ400R03W2K3024.msp
Japanese
http://support.citrix.com/servlet/KbServlet/download/13439-102-16730/P SJ400R03W2K3024.msp -
Citrix PSS400R03W2K3024.msp
Spanish
http://support.citrix.com/servlet/KbServlet/download/13437-102-16728/P SS400R03W2K3024.msp
Citrix MetaFrame Presentation Server 3.0
-
Citrix MPSE300R05W2K026.msi
http://support.citrix.com/servlet/KbServlet/download/13450-102-16741/M PSE300R05W2K026.msi -
Citrix MPSE300R05W2K3038.msi
http://support.citrix.com/servlet/KbServlet/download/13445-102-16736/M PSE300R05W2K3038.msi -
Citrix MPSF300R05W2K026.msi
French
http://support.citrix.com/servlet/KbServlet/download/13453-102-16744/M PSF300R05W2K026.msi -
Citrix MPSF300R05W2K3038.msi
French
http://support.citrix.com/servlet/KbServlet/download/13448-102-16739/M PSF300R05W2K3038.msi -
Citrix MPSG300R05W2K026.msi
German
http://support.citrix.com/servlet/KbServlet/download/13451-102-16742/M PSG300R05W2K026.msi -
Citrix MPSG300R05W2K3038.msi
German
http://support.citrix.com/servlet/KbServlet/download/13446-102-16737/M PSG300R05W2K3038.msi -
Citrix MPSJ300R05W2K026.msi
Japanese
http://support.citrix.com/servlet/KbServlet/download/13452-102-16743/M PSJ300R05W2K026.msi -
Citrix MPSJ300R05W2K3038.msi
Japanese
http://support.citrix.com/servlet/KbServlet/download/13447-102-16738/M PSJ300R05W2K3038.msi -
Citrix MPSS300R05W2K026.msi
Spanish
http://support.citrix.com/servlet/KbServlet/download/13454-102-16745/M PSS300R05W2K026.msi -
Citrix MPSS300R05W2K3038.msi
Spanish
http://support.citrix.com/servlet/KbServlet/download/13449-102-16740/M PSS300R05W2K3038.msi
References
Multiple Citrix Products Session Reliability Server Security Bypass Vulnerability
References:
References: