First published: Fri Jan 18 2008(Updated: )
Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Presentation Server | <=4.5 | |
Tgstation 13 | ||
Citrix Virtual Apps and Desktops | =1.0 | |
Citrix Access Essentials | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0356 is considered critical due to the potential for remote code execution.
To fix CVE-2008-0356, you should apply the latest patches and updates provided by Citrix for affected products.
CVE-2008-0356 affects Citrix MetaFrame Presentation Server versions up to 4.5, Access Essentials up to 2.0, and Desktop Server 1.0.
Yes, CVE-2008-0356 can be exploited remotely by an attacker sending specially crafted packets.
CVE-2008-0356 is a buffer overflow vulnerability that can lead to arbitrary code execution.