Citrix MetaFrame Client-Specified Published Applications Vulnerability
BID:5817
Info
Citrix MetaFrame Client-Specified Published Applications Vulnerability
| Bugtraq ID: | 5817 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2002 12:00AM |
| Updated: | Sep 27 2002 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Citrix MetaFrame XP SP2 Citrix MetaFrame XP SP1 Citrix MetaFrame XP |
| Not Vulnerable: | |
Discussion
Citrix MetaFrame Client-Specified Published Applications Vulnerability
Citrix MetaFrame XP family servers rely on client-supplied configuration when permitting access to published applications. Attackers may change the Citrix ICA Client .ICA configuration file to execute arbitrary programs instead of published applications.
Exploitation of this vulnerability may allow for remote compromise. The attacker must details about valid servers/published applications and be able to authenticate to exploit this issue.
.ICA files are only relied upon in Citrix networks that do not use a NFuse server to handle access to published applications.
Citrix MetaFrame XP family servers rely on client-supplied configuration when permitting access to published applications. Attackers may change the Citrix ICA Client .ICA configuration file to execute arbitrary programs instead of published applications.
Exploitation of this vulnerability may allow for remote compromise. The attacker must details about valid servers/published applications and be able to authenticate to exploit this issue.
.ICA files are only relied upon in Citrix networks that do not use a NFuse server to handle access to published applications.
Exploit / POC
Citrix MetaFrame Client-Specified Published Applications Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Citrix MetaFrame Client-Specified Published Applications Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Citrix MetaFrame Client-Specified Published Applications Vulnerability
References:
References:
- Hacking Citrix (sh0dan.org)