Citrix Metaframe XP Unspecified Buffer Overflow Vulnerability
Thursday, 23 December 2004 by Michel Roth
Thincomputing.net mentioned Citrix releasing Service Pack 4 for Citrix Metaframe XP yesterday. Turns out the Service Pack 4 fixes an unspecified buffer overflow vulnerability.

"A vulnerability has been reported in Citrix Metaframe XP, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an unspecified boundary error, which can be exploited to cause a buffer overflow.
Successful exploitation may allow execution of arbitrary code.

Solution:
Apply Service Pack 4 for Metaframe XP 1.0"

More info in the Secunia advisory and the Citrix Service Pack 4 support article.

Related Items:

Firefox IDN URL Domain Name Buffer Overflow (13 September 2005)
Trend Micro Products AntiVirus Library Buffer Overflow (27 February 2005)
F-Secure for Citrix Servers Critical Vulnerability (15 February 2005)
Citrix Program Neighborhood Agent Two Vulnerabilities (26 April 2005)
Citrix ICA Client ActiveX Control Heap Overflow Vulnerability (6 December 2006)
VMware NAT Networking Buffer Overflow Vulnerability (21 December 2005)
VMware ESX Server Multiple Vulnerabilities (5 April 2007)
Warning: 0-Day Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability (6 November 2006)
0-Day Microsoft Word 2000 Unspecified Code Execution Vulnerability (5 September 2006)
Citrix Presentation Server Client Unspecified Code Execution (2 March 2007)
Comments (0)add feed
password
 

busy