PT-2006-6496 · Citrix · Imasrv.Exe+4
Eric Detoisien
·
Publicado
2006-11-10
·
Atualizado
2018-10-17
·
CVE-2006-5821
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Citrix MetaFrame XP versions 1.0 through 2.0
Citrix Presentation Server versions 3.0 through 4.0
Description:
The issue is related to a heap-based buffer overflow in the
IMA SECURE DecryptData1 function within ImaSystem.dll. This allows remote attackers to execute arbitrary code by sending requests to the Independent Management Architecture (IMA) service, specifically ImaSrv.exe, with invalid size values that trigger the overflow during the decryption process.Recommendations:
For Citrix MetaFrame XP versions 1.0 through 2.0, update to a version that includes a fix for the heap-based buffer overflow in the IMA SECURE DecryptData1 function.
For Citrix Presentation Server versions 3.0 through 4.0, update to a version that includes a fix for the heap-based buffer overflow in the IMA SECURE DecryptData1 function.
As a temporary workaround, consider restricting access to the IMA service (ImaSrv.exe) to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Citrix Metaframe
Citrix Metaframe Presentation Server
Citrix Presentation Server
Imasrv.Exe
Imasystem.Dll