ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Citrix vulnerability found

Tom Espiner ZDNet.co.uk

Published: 02 Mar 2007 11:48 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability has been found in Citrix's Presentation Server Client, an application that allows remote users to access corporate servers from outside the office.

Versions older than 10.0 could be vulnerable to a buffer overflow which would enable an attacker to compromise a user's machine, according to researcher Karl Lynn of Juniper Networks, who discovered the vulnerability. Security advisory organisation Secunia has rated the vulnerability as highly critical in a security advisory.

The vulnerability is caused by an error in the support for ICA connections through a proxy server. This may be exploited to execute arbitrary code when a user visits a malicious web site, Citrix warned in an advisory.

ICA (Independent Computing Architecture), designed by Citrix, is a proprietary protocol for application server systems. The protocol gives specifications for passing data between servers and clients, regardless of platform.

The vulnerability currently has no patch, and Citrix recommends users protect themselves by upgrading to version 10.0 of Citrix Presentation Server Client.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
11 out of 11 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Citrix & Vmware Engineer 32,000 Warrington

Y ou will have experience in implementing and/or supporting Citrix servers/projects, coupled with In- depth knowledge of Microsoft Server 2003, ...

IT SUPPORT ANALYAT - BERKSHIRE - 22K - 25K

Skills required: - Novell Netware - Novell GroupWise - Novell ZenWorks for desktops - Citrix MetaFrame Presentation Server 4.0 - Office 2003/Office ...

Server Engineer @ Top Finance House - Wins/Citrix/VMWare

Vendor accreditations including MCSE and exposure to VMWare ESX, Distributed File Systems, Microsoft Clustering, Terminal Services and Citrix ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment