Vulnerability TSL and SSL protocols: Citrix upgrade the Secure Gateway, NetScaler and Access Gateway Enterprise - Update

Newly discovered vulnerability in the renegotiation protocol Transport Layer Security (TLS) and Secure Socket Layer (SSL) that could allow you to insert code at the beginning of a stream of data being protected.

So Citrix has released an update of the Secure Gateway to solve the problem. But this raises a question: all other products that use TLS / SSL (in particular Citrix Access Gateway Standard and Advanced) are immune?

For now you can download and update the Citrix Secure Gateway 3.0 and 3.1:

Update: Citrix has released an update to immediately NetScaler and Access Gateway Enterprise for which you need to update the firmware to at least version 8.1 build 68.7 to 99.8 and to build for version 9.1.

You can download updates to the following addresses:

Other articles on similar topics:

  1. Vulnerability in Citrix Secure Gateway 3.1.4
  2. Vulnerability in Citrix Secure Gateway 3.1
  3. New security bulletin: Cross Site Scripting Vulnerability in Citrix Access Gateway Enterprise Edition Logon Portal
  4. Citrix Secure Gateway version 3.1.2 arrives
  5. Access Gateway Enterprise Edition 8.0, Maintenance Build 50.3
  6. Citrix released Hotfix AAC450W005 for Access Gateway Advanced Edition 4.5
  7. Access Gateway Standard and Enterprise: New firmware released with the theme "carbon fiber"
  1. No comments yet ...
  1. No trackbacks yet ...

*
To test you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word