First published: Fri Dec 08 2006(Updated: )
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Presentation Server Client | <=9.200 | |
<=9.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6334 has a high severity rating due to the potential for remote code execution.
To fix CVE-2006-6334, upgrade to Citrix Presentation Server Client version 9.230 or later.
CVE-2006-6334 is a heap-based buffer overflow vulnerability.
CVE-2006-6334 affects Citrix Presentation Server Client versions up to 9.200 for Windows.
Yes, CVE-2006-6334 can be exploited remotely by malicious web sites.