PT-2004-1539 · Realnetworks · Helix Universal Server
Published
2004-04-17
·
Updated
2024-02-15
·
CVE-2004-0389
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
RealNetworks Helix Universal Server versions 9.0.1 through 9.0.2
Description
The issue allows remote attackers to cause a denial of service, resulting in a crash, via malformed requests that trigger a null dereference. This can be demonstrated using either GET PARAMETER or DESCRIBE requests.
Recommendations
For versions 9.0.1 and 9.0.2, consider restricting access to the server to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using malformed requests that could trigger a null dereference.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helix Universal Server