Citrix Presentation Server Lets Remote Authenticated Users Access Desktop Session Without Permission
|
|
SecurityTracker Alert ID: 1020027 |
|
SecurityTracker URL: http://securitytracker.com/id/1020027
|
|
CVE Reference:
CVE-2008-2300
(Links to External Site)
|
Updated: May 22 2008
|
Original Entry Date: May 15 2008
|
Impact:
User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 4.5 and prior versions
|
Description:
A vulnerability was reported in Citrix Presentation Server. A remote authenticated user can access a desktop session without authorization.
A remote authenticated user can gain access to a desktop running in the context of their own account.
Citrix Access Essentials versions 2.0 and prior are also affected.
Citrix Desktop Server 1.0 is also affected.
|
Impact:
A remote authenticated user can access a desktop session without authorization to access the desktop session.
|
Solution:
The vendor has issued the following fixes.
Citrix Presentation Server 4.5 for Windows Server 2003:
EN - http://support.citrix.com/article/CTX116960
FR - http://support.citrix.com/article/CTX116962
GE - http://support.citrix.com/article/CTX116961
JA - http://support.citrix.com/article/CTX116964
ES - http://support.citrix.com/article/CTX116963
Citrix Presentation Server 4.5 for Windows Server 2003 x64 Editions:
EN - http://support.citrix.com/article/CTX116954
FR - http://support.citrix.com/article/CTX116956
GE - http://support.citrix.com/article/CTX116957
JA - http://support.citrix.com/article/CTX116959
ES - http://support.citrix.com/article/CTX116958
Citrix Presentation Server 4.0 for Windows 2000 Server:
EN - http://support.citrix.com/article/CTX116521
FR - http://support.citrix.com/article/CTX116522
GE - http://support.citrix.com/article/CTX116528
JA - http://support.citrix.com/article/CTX116529
ES - http://support.citrix.com/article/CTX116527
Citrix Presentation Server 4.0 for Windows Server 2003:
EN - http://support.citrix.com/article/CTX116008
FR - http://support.citrix.com/article/CTX116523
GE - http://support.citrix.com/article/CTX116111
JA - http://support.citrix.com/article/CTX116009
ES - http://support.citrix.com/article/CTX116524
Citrix Access Essentials 2.0:
EN - http://support.citrix.com/article/CTX116960
FR - http://support.citrix.com/article/CTX116962
GE - http://support.citrix.com/article/CTX116961
JA - http://support.citrix.com/article/CTX116964
ES - http://support.citrix.com/article/CTX116963
Citrix Access Essentials 1.5:
EN - http://support.citrix.com/article/CTX116008
FR - http://support.citrix.com/article/CTX116523
GE - http://support.citrix.com/article/CTX116111
JA - http://support.citrix.com/article/CTX116009
ES - http://support.citrix.com/article/CTX116524
Citrix Access Essentials 1.0:
EN - http://support.citrix.com/article/CTX116008
FR - http://support.citrix.com/article/CTX116523
GE - http://support.citrix.com/article/CTX116111
JA - http://support.citrix.com/article/CTX116009
ES - http://support.citrix.com/article/CTX116524
Citrix Desktop Server 1.0 for Windows Server 2003:
EN - http://support.citrix.com/article/CTX116548
Citrix Desktop Server 1.0 for Windows Server 2003 x64 Editions:
EN - http://support.citrix.com/article/CTX116549
The vendor's advisory is available at:
http://support.citrix.com/article/CTX116941
|
Vendor URL: support.citrix.com/article/CTX116941 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 14 May 2008 22:17:25 -0400
Subject: Citrix Presentation Server
|
http://support.citrix.com/article/CTX116941
|
|