HIGH · 9.3

CVE-2010-2990

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client f...

Vulnerability Description

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CitrixIca Client For Linux<= 11.0
CitrixIca Client For Solaris<= 8.62
CitrixOnline Plug-In For Mac For Xenapp \& Xendesktop<= 10.0
CitrixOnline Plug-In For Windows For Xenapp \& Xendesktop<= 11.1
CitrixReceiver For Windows Mobile<= 11.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2990?

CVE-2010-2990 is a vulnerability with a CVSS score of 9.3 (HIGH). Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client f...

How severe is CVE-2010-2990?

CVE-2010-2990 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2990?

Check the references section above for vendor advisories and patch information. Affected products include: Citrix Ica Client For Linux, Citrix Ica Client For Solaris, Citrix Online Plug-In For Mac For Xenapp \& Xendesktop, Citrix Online Plug-In For Windows For Xenapp \& Xendesktop, Citrix Receiver For Windows Mobile.