PT-2011-4168 · Citrix · Citrix Access Gateway Enterprise Edition

Michal Trojnara

·

Published

2011-07-21

·

Updated

2011-09-22

·

CVE-2011-2882

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Citrix Access Gateway Enterprise Edition versions 8.1 through 8.1-67.7 Citrix Access Gateway Enterprise Edition versions 9.0 through 9.0-70.5 Citrix Access Gateway Enterprise Edition versions 9.1 through 9.1-96.4
Description A stack-based buffer overflow issue exists in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx. This allows remote attackers to execute arbitrary code via crafted HTTP header data.
Recommendations For Citrix Access Gateway Enterprise Edition versions 8.1 through 8.1-67.7, update to version 8.1-67.7 or later. For Citrix Access Gateway Enterprise Edition versions 9.0 through 9.0-70.5, update to version 9.0-70.5 or later. For Citrix Access Gateway Enterprise Edition versions 9.1 through 9.1-96.4, update to version 9.1-96.4 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2882

Affected Products

Citrix Access Gateway Enterprise Edition