CVE-2006-3779Out-of-bounds Read in Citrix Metaframe

CWE-125Out-of-bounds Read5 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.9%
top 23.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateMay 1

Description

Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages10 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-8626-56wx-533h: Citrix MetaFrame up to XP 12022-05-01

📋Vendor Advisories

3
Red Hat
openssl: Malformed X.509 IPAdressFamily could cause OOB read2017-08-28
Citrix
CVE-2006-3779: Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote2006-07-24
Citrix
Citrix Security Bulletin CTX110492