Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
BID:54754
Info
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
| Bugtraq ID: | 54754 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2592 CVE-2011-2593 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2012 12:00AM |
| Updated: | Aug 01 2012 12:00AM |
| Credit: | Dmitriy Pletnev, Secunia Research |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
The Citrix Access Gateway Plug-in ActiveX control is prone to multiple remote code-execution vulnerabilities because it fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit these issues to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Citrix Access Gateway Plug-in 9.3.49.5 is vulnerable; other versions may also be affected.
The Citrix Access Gateway Plug-in ActiveX control is prone to multiple remote code-execution vulnerabilities because it fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit these issues to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Citrix Access Gateway Plug-in 9.3.49.5 is vulnerable; other versions may also be affected.
Exploit / POC
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
Currently we are not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently we are not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
References:
References: