CVE-2012-4068
Published Jul 26, 2012
Last updated 7 years ago
Overview
- Description
- Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.1 allows remote attackers to execute arbitrary code via a crafted string associated with date and time data.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:citrix:provisioning_services:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B024564E-26BC-400B-A4FF-69E01D030B0E" }, { "criteria": "cpe:2.3:a:citrix:provisioning_services:5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69F3EE98-D3A9-4D41-A52E-F8579FAF3D07" }, { "criteria": "cpe:2.3:a:citrix:provisioning_services:5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C87C9440-780C-4A4C-8DA8-6E01FE9D8B08" }, { "criteria": "cpe:2.3:a:citrix:provisioning_services:5.6:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8A8EE11-52AF-405F-8B6A-51E088A941CC" }, { "criteria": "cpe:2.3:a:citrix:provisioning_services:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C84431E-0937-4DDE-A29B-E1030F21AAE1" }, { "criteria": "cpe:2.3:a:citrix:provisioning_services:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA5DD391-5B22-48FE-948E-D9DA78D3D82F" } ], "operator": "OR" } ] } ]