Lucene search

K
cve[email protected]CVE-2008-0356
HistoryJan 18, 2008 - 10:00 p.m.

CVE-2008-0356

2008-01-1822:00:00
CWE-119
web.nvd.nist.gov
30
cve-2008-0356
buffer overflow
citrix presentation server
ima service
remote code execution
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.84 High

EPSS

Percentile

98.5%

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.

Affected configurations

NVD
Node
citrixaccess_essentialsRange2.0
OR
citrixdesktop_serverMatch1.0
OR
citrixmetaframe_presentation_serverRange4.5
OR
citrixpresentation_server

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.84 High

EPSS

Percentile

98.5%