Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Broken Link for Citrix XenApp

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Citrix Systems
And, this specific program:
Citrix Program Neighborhood Client 9.x

This thread has been marked as resolved.
vicntc Broken Link for Citrix XenApp
Member 16th Mar, 2011 16:16
Ranking: 0
Posts: 5
User Since: 16th Mar, 2011
System Score: N/A
Location: CA
Citrix XenApp Online Plug-in 11.x 1 Insecure 11.0.0.5357 11.2.0.0
Install Solution
Detected Instances:
C:\Users\jcphilli\AppData\Local\Citrix\ICA Client\wfica32.exe, version 11.0.0.5357

Latest Version - patching one or more vulnerabilities:
11.2.0.0

Unfortunately, when you click on the link, it takes you to dead link at Citrix:
The content you have requested cannot be found.

I manually downloaded and installed the latest from Citrix, rebooted and rescanned but PSI still shows insecure.

Post "RE: Broken Link for Citrix XenApp" has been selected as an answer.
Anthony Wells RE: Broken Link for Citrix XenApp
Expert Contributor 17th Mar, 2011 12:34
Score: 2445
Posts: 3,332
User Since: 19th Dec 2007
System Score: N/A
Location: N/A
Last edited on 17th Mar, 2011 12:38
Hi ,

There would seem to be an unpatched vulnerability (dating from August 2010) in your programme/app version 11.x as per this Secunia Advisory , which is patched in version 12.0.3 apparently :-

http://secunia.com/advisories/40821/

Version 12.0.3 is secure (with one partial fix) as per :-

http://secunia.com/advisories/product/31371/?task=...

Which version have you updated to on your system ??
Do you have a secure version listed on the results page ??
What is the detected instance pathway that is continuing to show as "insecure" ??

Anthony


--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+1
-0
vicntc RE: Broken Link for Citrix XenApp
Member 17th Mar, 2011 16:03
Score: 0
Posts: 5
User Since: 16th Mar 2011
System Score: N/A
Location: CA
The version I have is listed in my reply.

The issue I was reporting is that the link provided by PSI to "fix" the version is broken. So, when you click on the "Install Solution" link, it takes you to:

http://www.citrix.com/contentproblem.asp?url=%2FEn...

and results in:

The content you have requested cannot be found.
Was this reply relevant?
+0
-0
Anthony Wells RE: Broken Link for Citrix XenApp
Expert Contributor 17th Mar, 2011 16:20
Score: 2445
Posts: 3,332
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

If you wish to have my help , you need to answer my questions in detail as I have requested . I did not ask to waste your time and most definitely not mine .

Your reply does not tell me which version you have updated to nor it's detected instance pathway !!

To report/fix the incorrect/broken link , you will need support to pick up this thread or you can contact them at support@secunia.com by email .

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
Maurice Joyce RE: Broken Link for Citrix XenApp
Handling Contributor 18th Mar, 2011 01:02
Score: 11743
Posts: 9,000
User Since: 4th Jan 2009
System Score: N/A
Location: UK
I am not sure the link is incorrect but rather that part of the web page sponsored by Citrix shows an error.

I clicked the PSI link U gave on your post:

http://www.citrix.com/contentproblem.asp?url=%2FEn...

That took me to a slightly incomplete web page but with a clearly visible DOWNLOAD link.

I clicked that & ended up here:

http://www.citrix.com/English/ss/downloads/index.a...

I filled in the search box with XenApp which took me here:

http://www.citrix.com/English/ss/downloads/results...

That reveals a series of downloads including version 12.1 for Windows if I have inserted the correct data for your application.

For a more refined answers there is an option to fill out more information.

The workings of the download link look fairly normal to me apart from the missing Citrix content which does not prevent finding & installing any updates as Secunia intended.





--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+1
-0
vicntc RE: Broken Link for Citrix XenApp
Member 18th Mar, 2011 05:28
Score: 0
Posts: 5
User Since: 16th Mar 2011
System Score: N/A
Location: CA
I'm not trying to waste anyones time, I thought I had answered the questions you asked. If I didn't provide the correct information, can you rephrase what you were looking for and where I should look for it?
Was this reply relevant?
+0
-0
vicntc RE: Broken Link for Citrix XenApp
Member 18th Mar, 2011 05:32
Score: 0
Posts: 5
User Since: 16th Mar 2011
System Score: N/A
Location: CA
Thank you.

I agree but, and I am new to PSI, when I click on other links they take you right to a spot or start the install etc. This particular link did not. That seemed to indicate that the PSI link was not going where it should.

I will capture this thread and send it to the secunia email address provided above.

Thank you both for your assistance.
Was this reply relevant?
+0
-0
Maurice Joyce RE: Broken Link for Citrix XenApp
Handling Contributor 18th Mar, 2011 09:14
Score: 11743
Posts: 9,000
User Since: 4th Jan 2009
System Score: N/A
Location: UK
A good idea. I do not use the solution button but I think it takes U to the vendor site so that U can easily find the download U want.

I do not think it is designed to take U to an exact link to satisfy your PC download requirement.

Worth checking with Secunia Support or wait for others that use that link to clarify.

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+0
-0
M.Hansen RE: Broken Link for Citrix XenApp
Secunia Official 18th Mar, 2011 10:32
Score: 188
Posts: 410
User Since: 26th Jan 2009
System Score: N/A
Location: Copenhagen, DK
Hi
Thank you for reporting the dead link for Citrix XenApp Online Plug-in 11.x

I've updated our link to:
http://www.citrix.com/English/ss/downloads/results...

The changes should take effect after a rescan with the Secunia PSI.

Anthony Wells RE: Broken Link for Citrix XenApp
Expert Contributor 18th Mar, 2011 12:39
Score: 2445
Posts: 3,332
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello again ,

Now that Morten has corrected the link for this app., you should be able to update to version 12.1 , which is later version than 12.0.3 , which should be recorded and displayed as secure by the PSI ; that means you should see an entry for it (in alphabetical order) on the "Scan Results" page of the PSI .

You will (probably) need to do a full PSI scan to ensure a correct display by the PSI and a reboot often helps ensure a correct programme update .

If you still have an old/out of date/insecure file of version 11.x it will either : 1)display out of alphabetical order at the top of the Scan results page : or : 2)as a second "zombie" file in the 12.1 programme listing (click the [+] sign next to the/any programme entry to see the "detected instances") .

Tell us what you can see for all your Citrix XenApp "detected instances" .

If I have not been clear , please ask again .

Take care

Anthony






--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
Anthony Wells RE: Broken Link for Citrix XenApp
Expert Contributor 20th Mar, 2011 13:39
Score: 2445
Posts: 3,332
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello @vicntc ,

Are you now up to date with the PSI @ 100% ??

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
vicntc RE: Broken Link for Citrix XenApp
Member 20th Mar, 2011 18:04
Score: 0
Posts: 5
User Since: 16th Mar 2011
System Score: N/A
Location: CA
Yes, it appears I am... After uninstalling v11, installing v12 and running a new scan I am back to Green/100%.

And the link is fixed in PSI as well. It now takes you to the page that displays the items for download.

Thank you all for your assistance.
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability