---------------------------------------------------------------------- Do you need accurate and reliable IDS / IPS / AV detection rules? Get in-depth vulnerability details: http://secunia.com/binary_analysis/sample_analysis/ ---------------------------------------------------------------------- TITLE: Citrix Web Interface Improper Session Termination Security Issue SECUNIA ADVISORY ID: SA32444 VERIFY ADVISORY: http://secunia.com/advisories/32444/ CRITICAL: Less critical IMPACT: Security Bypass WHERE: Local system SOFTWARE: Citrix Web Interface 5.x http://secunia.com/advisories/product/20251/ DESCRIPTION: A security issue has been reported in Citrix Web Interface, which can be exploited by malicious, local users to bypass certain security restrictions. The security issue is caused due to the application improperly terminating a user session and can be exploited to gain access to the session via the same browser instance. Successful exploitation requires valid Citrix Web Interface credentials and access to the victim's browser instance. The security issue affects versions 5.0 and 5.0.1 when deployed with a Java application server. SOLUTION: Update to version 5.0.2. https://www.citrix.com/site/SS/downloads/ PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://support.citrix.com/article/CTX118768 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------