PT-2006-6946 · Citrix · Citrix Presentation Server Client

Aaron Portnoy

+1

·

Published

2006-12-08

·

Updated

2018-10-17

·

CVE-2006-6334

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Citrix Presentation Server Client versions prior to 9.230 for Windows
Description A heap-based buffer overflow issue exists in the SendChannelData function within wfica.ocx. This allows remote malicious websites to execute arbitrary code by manipulating the DataSize parameter to be less than the length of the Data buffer.
Recommendations For versions prior to 9.230, update to version 9.230 or later to resolve the issue. As a temporary workaround, consider restricting access to the SendChannelData function until a patch is applied. Avoid using the DataSize parameter in the affected function with values less than the length of the Data buffer until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6334

Affected Products

Citrix Presentation Server Client