Two Vulnerabilities in Citrix Program Neighborhood Agent

The Citrix Program Neighborhood Agent contains an unchecked buffer that could allow an intruder to run arbitrary code on an affected system.

ITPro Today

April 25, 2005

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedApril 26 2005 by iDEFENSE

VERSIONS AFFECTED

ProgramNeighborhood Agent for Win32

DESCRIPTION

The Citrix ProgramNeighborhood Agent contains an unchecked buffer that could allow anintruder to run arbitrary code on an affected system. The code wouldrun in the same security context as the user who is currently logged into the system. The problem exists due to the way the agent softwarebuilds the filenames of icons associated with cache applications.

A second vulnerability could allow an intruder to create arbitrary shortcuts in a user's startup folder.

VENDOR RESPONSE

Citrix Systems hasreleased updated versions of its client packages along with an article,"Vulnerabilitiesin Program Neighborhood Agent could allow arbitrary code execution,"that describes the problem.

CREDITS:

The unchecked buffer vulnerability was discovered by PatrikKarlsson and reported in conjunction with iDEFENSE. The shortcut creation vulnerability was discovered by iDEFENSE.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like