PT-2006-6496 · Citrix · Imasrv.Exe+4

Eric Detoisien

·

Publicado

2006-11-10

·

Atualizado

2018-10-17

·

CVE-2006-5821

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Citrix MetaFrame XP versions 1.0 through 2.0 Citrix Presentation Server versions 3.0 through 4.0
Description: The issue is related to a heap-based buffer overflow in the IMA SECURE DecryptData1 function within ImaSystem.dll. This allows remote attackers to execute arbitrary code by sending requests to the Independent Management Architecture (IMA) service, specifically ImaSrv.exe, with invalid size values that trigger the overflow during the decryption process.
Recommendations: For Citrix MetaFrame XP versions 1.0 through 2.0, update to a version that includes a fix for the heap-based buffer overflow in the IMA SECURE DecryptData1 function. For Citrix Presentation Server versions 3.0 through 4.0, update to a version that includes a fix for the heap-based buffer overflow in the IMA SECURE DecryptData1 function. As a temporary workaround, consider restricting access to the IMA service (ImaSrv.exe) to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5821

Produtos afetados

Citrix Metaframe
Citrix Metaframe Presentation Server
Citrix Presentation Server
Imasrv.Exe
Imasystem.Dll