---------------------------------------------------------------------- Secunia is pleased to announce the release of the annual Secunia report for 2008. Highlights from the 2008 report: * Vulnerability Research * Software Inspection Results * Secunia Research Highlights * Secunia Advisory Statistics Request the full 2008 Report here: http://secunia.com/advisories/try_vi/request_2008_report/ Stay Secure, Secunia ---------------------------------------------------------------------- TITLE: Citrix Presentation Server Access Gateway Filters Security Bypass SECUNIA ADVISORY ID: SA34865 VERIFY ADVISORY: http://secunia.com/advisories/34865/ DESCRIPTION: A vulnerability has been reported in Citrix Presentation Server, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to the improper enforcing of access policies defined using Access Gateway Advanced Edition filters and can be exploited to bypass intended access restrictions. The vulnerability is reported in Citrix XenApp (formerly Presentation Server) version 4.5 with Hotfix Rollup Pack 3 installed. SOLUTION: Apply Hotfix Rollup Pack 4. -- Citrix XenApp 4.5 for Windows Server 2003 -- EN: http://support.citrix.com/article/CTX119069 ES: http://support.citrix.com/article/CTX119074 FR: http://support.citrix.com/article/CTX119071 DE: http://support.citrix.com/article/CTX119072 JA: http://support.citrix.com/article/CTX119073 RU: http://support.citrix.com/article/CTX119471 -- Citrix XenApp 4.5 for Windows Server 2003 x64 Editions -- EN: http://support.citrix.com/article/CTX119075 ES: http://support.citrix.com/article/CTX119079 FR: http://support.citrix.com/article/CTX119076 DE: http://support.citrix.com/article/CTX119077 JA: http://support.citrix.com/article/CTX119078 PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://support.citrix.com/article/CTX118792 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------