First published: Fri Nov 10 2006(Updated: )
The Independent Management Architecture (IMA) service (ImaSrv.exe) in Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to cause a denial of service (service exit) via a crafted packet that causes the service to access an unmapped memory address and triggers an unhandled exception.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix MetaFrame | =1.0 | |
Citrix MetaFrame | =2.0 | |
Citrix Presentation Server | =3.0 | |
Citrix Presentation Server | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5861 has been classified with a high severity, as it allows for remote denial of service attacks.
To mitigate CVE-2006-5861, upgrade to the latest version of Citrix MetaFrame XP or Presentation Server as provided by Citrix.
CVE-2006-5861 affects Citrix MetaFrame XP versions 1.0 and 2.0, and Citrix Presentation Server versions 3.0 and 4.0.
CVE-2006-5861 can be exploited via a crafted packet sent to the IMA service to trigger a denial of service.
While specific exploitation details vary, CVE-2006-5861 poses a risk that can be abused if the vulnerable Citrix services are not updated or secured.