Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-0356 | First vendor Publication | 2008-01-18 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0356 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
40860 | Citrix Presentation Server Independent Management Architecture (IMA) Service ... A remote overflow exists in Citrix Presentation Server Independent Management Architecture Service. The service fails to validate a parameter used for memory allocation, which may result in a heap overflow if an attacker sends an overly large packet. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of confidentiality, integrity, or availability. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2008-01-30 | IAVM : 2008-T-0004 - Citrix Presentation Server IMA Service Buffer Overflow Vulnerability Severity : Category II - VMSKEY : V0015730 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Citrix MetaFrame IMA buffer overflow attempt RuleID : 13519 - Revision : 9 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-30 | Name : The remote host has a virtualization application installed that is affected b... File : citrix_presentation_server_ctx114487.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:15:17 |
|
2024-11-28 12:14:39 |
|
2021-05-04 12:07:00 |
|
2021-04-22 01:07:28 |
|
2020-05-23 01:39:00 |
|
2020-05-23 00:21:08 |
|
2018-10-16 00:19:25 |
|
2016-04-27 09:28:46 |
|
2016-04-26 17:02:25 |
|
2014-02-17 10:43:31 |
|
2014-01-19 21:24:45 |
|
2013-11-11 12:37:50 |
|
2013-05-11 00:07:19 |
|