First published: Thu Jul 26 2007(Updated: )
Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 have unknown impact and attack vectors, possibly related to buffer overflows. NOTE: vector 3 might overlap CVE-2007-3679.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Access Gateway Plug-in | <=4.5 | |
Firefox | ||
Citrix Endpoint Analysis Client | ||
Citrix Access Gateway Plug-in | <=4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4013 has not been explicitly assigned a CVSS score, but it is considered critical due to multiple vulnerabilities in widely used software.
To mitigate CVE-2007-4013, upgrade to the latest versions of Citrix Access Gateway and the Citrix Endpoint Analysis Client that contain security patches.
CVE-2007-4013 affects versions of Citrix Access Gateway up to 4.5 and certain versions of the Citrix Endpoint Analysis Client.
CVE-2007-4013 impacts Citrix Access Gateway, Citrix Endpoint Analysis Client, and Mozilla Firefox plugins utilizing specific DLLs.
CVE-2007-4013 can potentially be exploited by specially crafted inputs targeting the vulnerabilities in the affected DLLs.