CVE-2012-4068
Citrix Provisioning Services 5.0-6.1 - Remote Code Execution via SoapServer Date/Time String
Title source: llmDescription
Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.1 allows remote attackers to execute arbitrary code via a crafted string associated with date and time data.
References (5)
Core 5
Core References
Patch third-party-advisory
x_refsource_idefense
http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=979
Patch x_refsource_confirm
http://support.citrix.com/article/ctx133039
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75311
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1027004
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/81664
Scores
EPSS
0.0529
EPSS Percentile
90.1%
Details
CWE
CWE-119
Status
published
Products (5)
citrix/provisioning_services
5.0
citrix/provisioning_services
5.1
citrix/provisioning_services
5.6 (2 CPE variants)
citrix/provisioning_services
6.0
citrix/provisioning_services
6.1
Published
Jul 26, 2012
Tracked Since
Feb 18, 2026