Two Vulnerabilities in Citrix Program Neighborhood Agent
The Citrix Program Neighborhood Agent contains an unchecked buffer that could allow an intruder to run arbitrary code on an affected system.
April 25, 2005
ReportedApril 26 2005 by iDEFENSE
VERSIONS AFFECTED
ProgramNeighborhood Agent for Win32 |
DESCRIPTION
The Citrix ProgramNeighborhood Agent contains an unchecked buffer that could allow anintruder to run arbitrary code on an affected system. The code wouldrun in the same security context as the user who is currently logged into the system. The problem exists due to the way the agent softwarebuilds the filenames of icons associated with cache applications.
A second vulnerability could allow an intruder to create arbitrary shortcuts in a user's startup folder.
VENDOR RESPONSE
Citrix Systems hasreleased updated versions of its client packages along with an article,"Vulnerabilitiesin Program Neighborhood Agent could allow arbitrary code execution,"that describes the problem.
CREDITS:
The unchecked buffer vulnerability was discovered by PatrikKarlsson and reported in conjunction with iDEFENSE. The shortcut creation vulnerability was discovered by iDEFENSE.
About the Author
You May Also Like