Episode #946 Quiz
Citrix Bleed
Date: 2023-10-31 | Length: 1.75 hrs | Episode page at twit.tv
About this episode
Citrix Bleed (CVE-2023-4966) affected Citrix NetScaler ADC/Gateway. Assetnote reverse engineered patched nsppe binaries with Ghidra/BinDiff and found an unauthenticated OpenID endpoint using snprintf safely, then wrongly reusing snprintf’s returned required length as the response size. This overread leaked adjacent RAM, including session tokens, enabling authentication bypass and mass exploitation.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.