Vulnerabilities > CVE-2006-6334 - Buffer Overflow vulnerability in Citrix Presentation Server Client WFICA.OCX ActiveX Component Heap

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
citrix
exploit available

Summary

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.

Vulnerable Configurations

Part Description Count
Application
Citrix
1

Exploit-Db

  • descriptionCitrix Presentation Server Client WFICA.OCX ActiveX Heap BOF Exploit. CVE-2006-6334. Remote exploit for windows platform
    fileexploits/windows/remote/5106.html
    idEDB-ID:5106
    last seen2016-01-31
    modified2008-02-12
    platformwindows
    port
    published2008-02-12
    reporterElazar
    sourcehttps://www.exploit-db.com/download/5106/
    titleCitrix Presentation Server Client - WFICA.OCX ActiveX Heap BoF Exploit
    typeremote
  • descriptionCitrix Presentation Server Client 9.200 WFICA.OCX ActiveX Component Heap Buffer Overflow Vulnerability. CVE-2006-6334. Remote exploit for windows platform
    idEDB-ID:29230
    last seen2016-02-03
    modified2006-12-06
    published2006-12-06
    reporterAndrew Christensen
    sourcehttps://www.exploit-db.com/download/29230/
    titleCitrix Presentation Server Client 9.200 - WFICA.OCX ActiveX Component Heap Buffer Overflow Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/63580/citrix-overflow.txt
idPACKETSTORM:63580
last seen2016-12-05
published2008-02-13
reporterElazar Broad
sourcehttps://packetstormsecurity.com/files/63580/citrix-overflow.txt.html
titlecitrix-overflow.txt

Seebug

  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:82752
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-82752
    titleCitrix Presentation Server Client 9.200 WFICA.OCX ActiveX Component Heap Buffer Overflow Vulnerability
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:65194
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-65194
    titleCitrix Presentation Server Client WFICA.OCX ActiveX - Heap BOF Exploit
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:8090
    last seen2017-11-19
    modified2008-02-14
    published2008-02-14
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-8090
    titleCitrix Presentation Server Client WFICA.OCX ActiveX Heap BOF Exploit