Citrix EdgeSight for Endpoints and Presentation Server Database 信息泄露漏洞

漏洞信息详情

Citrix EdgeSight for Endpoints and Presentation Server Database 信息泄露漏洞

漏洞简介

Presentation Server的Citrix EdgeSight 4.2和4.5, Endpoints的EdgeSight 4.2和4.5,以及 for NetScaler 1.0和 1.1 的 EdgeSight,不能再设置文件中正确储存数据库资格,使本地用户获得敏感信息。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Citrix EdgeSight for Presentation Server 4.5

Citrix EdgeSight 4.5 Service Pack 2 (SP2)

http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip

Citrix EdgeSight for Presentation Server 4.2

Citrix EdgeSight 4.5 Service Pack 2 (SP2)

http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip

Citrix EdgeSight for Endpoints 4.5

Citrix EdgeSight 4.5 Service Pack 2 (SP2)

http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip

Citrix EdgeSight for Endpoints 4.2

Citrix EdgeSight 4.5 Service Pack 2 (SP2)

http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip

参考网址

来源: BID

名称: 26705

链接:http://www.securityfocus.com/bid/26705

来源: support.citrix.com

链接:http://support.citrix.com/article/CTX115281

来源: VUPEN

名称: ADV-2007-4091

链接:http://www.frsirt.com/english/advisories/2007/4091

来源: SECUNIA

名称: 27935

链接:http://secunia.com/advisories/27935

来源: XF

名称: edgesight-configuration-file-info-disclosure(38861)

链接:http://xforce.iss.net/xforce/xfdb/38861

来源: SECTRACK

名称: 1019050

链接:http://www.securitytracker.com/id?1019050

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享