CVE-2011-2593
Citrix Access Gateway Plug-in for Windows nsepacom Integer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based buffer overflow.
Desbordamiento de enteros en el método StartEpa en el control nsepacom ActiveX (nsepa.exe) en Citrix Access Gateway Enterprise Edition Plug-in para Windows 9.x anterior a 9.3-57.5 y 10.0 anterior a 10.0-69.4 permite a atacantes remotos ejecutar código arbitrario a través de una cabecera Content-Length HTTP manipulada, lo que provoca un desbordamiento de buffer basado en memoria dinámica.
Secunia Research has discovered a vulnerability in Citrix Access Gateway Plug-in for Windows, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused by an integer overflow error in the nsepacom ActiveX control (nsepa.exe) when processing HTTP responses based on the request via the "StartEpa()" method. This can be exploited to cause a heap-based buffer overflow via a specially crafted "Content-Length" HTTP response header. Successful exploitation may allow execution of arbitrary code. Citrix Access Gateway Plug-in for Windows version 9.3.49.5 is affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-06-29 CVE Reserved
- 2012-08-01 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/45299 | Third Party Advisory | |
http://secunia.com/secunia_research/2012-26 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77317 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://support.citrix.com/article/CTX134303 | 2017-08-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Access Gateway Plug-in Search vendor "Citrix" for product "Access Gateway Plug-in" | <= 9.3 Search vendor "Citrix" for product "Access Gateway Plug-in" and version " <= 9.3" | 49-5, enterprise, windows |
Affected
| ||||||
Citrix Search vendor "Citrix" | Access Gateway Plug-in Search vendor "Citrix" for product "Access Gateway Plug-in" | 10.0 Search vendor "Citrix" for product "Access Gateway Plug-in" and version "10.0" | enterprise, windows |
Affected
|