漏洞信息详情
Citrix EdgeSight for Endpoints and Presentation Server Database 信息泄露漏洞
- CNNVD编号:CNNVD-200712-081
- 危害等级: 低危
- CVE编号:
CVE-2007-6267
- 漏洞类型:
信任管理
- 发布时间:
2007-12-07
- 威胁类型:
本地
- 更新时间:
2007-12-07
- 厂 商:
citrix - 漏洞来源:
Citrix -
漏洞简介
Presentation Server的Citrix EdgeSight 4.2和4.5, Endpoints的EdgeSight 4.2和4.5,以及 for NetScaler 1.0和 1.1 的 EdgeSight,不能再设置文件中正确储存数据库资格,使本地用户获得敏感信息。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Citrix EdgeSight for Presentation Server 4.5
Citrix EdgeSight 4.5 Service Pack 2 (SP2)
http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip
Citrix EdgeSight for Presentation Server 4.2
Citrix EdgeSight 4.5 Service Pack 2 (SP2)
http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip
Citrix EdgeSight for Endpoints 4.5
Citrix EdgeSight 4.5 Service Pack 2 (SP2)
http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip
Citrix EdgeSight for Endpoints 4.2
Citrix EdgeSight 4.5 Service Pack 2 (SP2)
http://support.citrix.com/servlet/KbServlet/download/15280-102-17800/E dgeSight%204.5%20Service%20Pack%202.zip
参考网址
来源: BID
名称: 26705
链接:http://www.securityfocus.com/bid/26705
来源: support.citrix.com
链接:http://support.citrix.com/article/CTX115281
来源: VUPEN
名称: ADV-2007-4091
链接:http://www.frsirt.com/english/advisories/2007/4091
来源: SECUNIA
名称: 27935
链接:http://secunia.com/advisories/27935
来源: XF
名称: edgesight-configuration-file-info-disclosure(38861)
链接:http://xforce.iss.net/xforce/xfdb/38861
来源: SECTRACK
名称: 1019050