News
News
1/25/2007
06:22 PM
50%
50%

Citrix Patches Critical Presentation Server Flaw

Citrix has fixed a buffer overflow vulnerability in its widely used Presentation Server software that could allow remote attackers to execute malicious code.

Citrix has fixed a buffer overflow vulnerability in its widely used Presentation Server software that could allow remote attackers to execute malicious code.

In a Tuesday advisory, Citrix said the flaw affects the software's print provider component, which lets users print to local printers from published applications.

Citrix Presentation Server is an application virtualization solution that allows remote users to securely access virtualized client/server applications. All versions of Citrix MetaFrame XP and Presentation Server up to and including 4.0 are affected, the vendor said.

Attackers could exploit the vulnerability through a local API call or through an unauthenticated Remote Procedure Call (RPC) request. However, a miscreant would need to have access to the RPC interface to exploit the flaw, which companies with Presentation Server deployments don't typically make accessible from outside, according to the advisory.

In a blog post, the SANS Internet Storm Center recommended that Presentation Server users apply the patch because an exploit for the vulnerability has already appeared.

Fort Lauderdale, Fla.-based Citrix rated the severity of the flaw as "high," the vendor's most critical rating. Symantec Deepsight had a similar view, rating its severity as 10 on a 10-point scale. But Danish research firm Secunia wasn't as concerned, assigning a threat score of 3 on a 5-point scale, or "moderately critical," to the vulnerability.

In November, Citrix fixed a pair of remotely exploitable vulnerabilities in its Presentation Server platform that could allow miscreants to trigger buffer overflows and launch denial of service attacks.

Comment  | 
Print  | 
More Insights
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest, Dec. 9, 2014
Apps will make or break the tablet as a work device, but don't shortchange critical factors related to hardware, security, peripherals, and integration.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of December 14, 2014. Be here for the show and for the incredible Friday Afternoon Conversation that runs beside the program.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.