English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Citrix Access Gateway Plug-in for Windows nsepacom ActiveX Control Vulnerabilities


Secunia ID

SA45299

CVE-ID

CVE-2011-2592, CVE-2011-2593

Release Date

01 Aug 2012

Last Change

10 Aug 2012

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Citrix Access Gateway Plug-in for Windows 9.x
Citrix nsepacom ActiveX Control 9.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Secunia Research has discovered two vulnerabilities in Citrix Access Gateway Plug-in for Windows, which can be exploited by malicious people to compromise a user's system.

1) A boundary error in the nsepacom ActiveX control (nsepa.exe) when processing HTTP responses based on the request via the "StartEpa()" method can be exploited to cause a heap-based buffer overflow via an overly long "CSEC" HTTP response header.

2) An integer overflow error in the nsepacom ActiveX control (nsepa.exe) when processing HTTP responses based on the request via the "StartEpa()" method can be exploited to cause a heap-based buffer overflow via a specially crafted "Content-Length" HTTP response header.

Successful exploitation of the vulnerabilities allows execution of arbitrary code.

The vulnerabilities are confirmed in version 9.3.49.5 and reportedly affect the following versions:
* 10.0 prior to 10.0-69.4
* 9.3 prior to 9.3-57.5
* 9.2 (all versions)
* 9.1 (all versions)
* 9.0 (all versions)

Solution

Update to version 10.0-69.4 or 9.3-57.5.
https://www.citrix.com/English/ss/downloads/results.asp?productID=15005

Reported by

Dmitriy Pletnev, Secunia Research.

Original Advisory

Secunia Research:
http://secunia.com/secunia_research/2012-26/
http://secunia.com/secunia_research/2012-27/

Citrix:
http://support.citrix.com/article/CTX134303