PT-2009-1387 · Realnetworks · Helix Server+1

Publicado

2009-01-20

·

Atualizado

2011-03-08

·

CVE-2008-5911

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealNetworks Helix Server and Helix Mobile Server versions 11.x through 11.1.7 RealNetworks Helix Server and Helix Mobile Server versions 12.x through 12.0.0
Description The issue allows remote attackers to cause a denial of service or execute arbitrary code. This can be achieved through various means, including crafted RTSP SETUP commands, an NTLM authentication request with malformed base64-encoded data, an RTSP DESCRIBE command, or a DataConvertBuffer request.
Recommendations For versions 11.x through 11.1.7, update to version 11.1.8 or later. For versions 12.x through 12.0.0, update to version 12.0.1 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5911

Produtos afetados

Helix Mobile Server
Helix Server