Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
BID:27329
Info
Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
| Bugtraq ID: | 27329 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0356 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | TippingPoint and the ZDI are credited with the discovery of this issue. |
| Vulnerable: |
Citrix Presentation Server 4.0 Citrix Presentation Server 4.5 Citrix MetaFrame Presentation Server 3.0 Citrix Desktop Server 1.0 x64 Citrix Desktop Server 1.0 Citrix Access Essentials 2.0 Citrix Access Essentials 1.5 Citrix Access Essentials 1.0 |
| Not Vulnerable: | |
Discussion
Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
Citrix Presentation Server is prone to a buffer-overflow vulnerability because the IMA service fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of the IMA server process. Failed exploit attempts will likely result in denial-of-service conditions.
The issue affects the following versions:
Citrix MetaFrame and Presentation Server 4.5 (and earlier)
Citrix Access Essentials 2.0 (and earlier)
Citrix Desktop Server 1.0 (and earlier)
Citrix Presentation Server is prone to a buffer-overflow vulnerability because the IMA service fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of the IMA server process. Failed exploit attempts will likely result in denial-of-service conditions.
The issue affects the following versions:
Citrix MetaFrame and Presentation Server 4.5 (and earlier)
Citrix Access Essentials 2.0 (and earlier)
Citrix Desktop Server 1.0 (and earlier)
Exploit / POC
Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
DSquare Security has developed a working commercial exploit for its D2 Exploitation Pack product. This exploit is not otherwise publicly available or known to be circulating in the wild.
DSquare Security has developed a working commercial exploit for its D2 Exploitation Pack product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
References
Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
References:
References:
- Citrix Presentation Server Home Page (Citrix)
- ZDI-08-002: Citrix Presentation Server IMA Service Heap Overflow Vulnerability (ZDI)
- CTX114487 - Vulnerability in Presentation Server's IMA Service could result in a (Citrix)
- Vulnerability Note VU#412228 Citrix Presentation Server heap based buffer overfl (US-CERT)
- ZDI-08-002 Citrix Presentation Server IMA Service Heap Overflow Vulnerability (Zero Day Initiative)