40860 : Citrix Presentation Server Independent Management Architecture (IMA) Service TCP Packet Handling Remote Overflow
Printer | http://osvdb.org/40860 | Email This | Edit Vulnerability

Views This Week

3

Views All Time

28

Info

Last Modified

2 months ago

Percent Complete

100%

Disclosure

Jan 17, 2008

Discovery

Jul 20, 2007

Dates

Exploit

Unknown

Solution

Jan 15, 2008

Description

A remote overflow exists in Citrix Presentation Server Independent Management Architecture Service. The service fails to validate a parameter used for memory allocation, which may result in a heap overflow if an attacker sends an overly large packet. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of confidentiality, integrity, or availability.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity, Loss of Availability
Solution: Patch
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Technical

The process trusts a user-suppled value as a parameter to a memory allocation. By supplying a specific value, an undersized heap buffer may be allocated. Subsequently, an attacker can then overflow that heap buffer by sending an overly large packet leading to arbitrary code execution in the context of the SYSTEM user.

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Citrix has released a patch to address this vulnerability.

Products

Citrix
Watch-list
Presentation Server
Watch-list
4.5

References

Tools & Filters

Snort

13519

Credit

  • Eric Detoisien - eric.detoisienBrand New Doo Dooglobal-secure.fr - Global Secure

Blogs

None found at this time

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use