📄 9325.txt
字号:
Rule--Sid9325--Summary:This event is generated when an attempt is made to cause a Denial of Service (DoS) in Citrix IMA.--Impact:Denial of Service (DoS)--Detailed Information:The Citrix MetaFrame product line is managed by the Independent Management Architecture (IMA). Management connections to this service occur over TCP port 2513. Messages to this service begin with the following format:0x0000 0x04 Message size in bytes (includes size field)0x0004 0x04 Unknown field0x0008 0x04 Event Data Length0x000C 0x10 Other event headers0x001C 0x02 Event ID0x001E 0x02 Data Version0x0020 0x01 Header Version0x0021 0x01 flag0x0022 0x02 Description Length0x0024 BEGIN ENCRYPTED DATAIf the message is of size 0x1c (both in reality, and in the message size field) and the event data length is 0, the message will pass the validity checks and be passed to the to a function that will attempt to process the event header. However, because it doesn't exist, the program will access invalid data areas and a memory access violation may occur.--Affected Systems:Citrix Presentation Server 4.0Citrix MetaFrame Presentation Server 4.0Citrix MetaFrame Presentation Server 3.0Citrix MetaFrame XPsCitrix MetaFrame XPeCitrix MetaFrame XPaCitrix MetaFrame XP SP2Citrix MetaFrame XP SP1Citrix MetaFrame XP--Attack Scenarios:An attacker would need to supply malformed data to the Cisco MetaFrame server.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Apply the appropriate vendor supplied patches.Upgrade to the latest non-affected version of the software.--Contributors:Sourcefire Vulnerability Research TeamMatthew Olney <matthew.olney@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -