PT-2009-1387 · Realnetworks · Helix Server+1
Published
2009-01-20
·
Updated
2011-03-08
·
CVE-2008-5911
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealNetworks Helix Server and Helix Mobile Server versions 11.x through 11.1.7
RealNetworks Helix Server and Helix Mobile Server versions 12.x through 12.0.0
Description
The issue allows remote attackers to cause a denial of service or execute arbitrary code. This can be achieved through various means, including crafted RTSP SETUP commands, an NTLM authentication request with malformed base64-encoded data, an RTSP DESCRIBE command, or a DataConvertBuffer request.
Recommendations
For versions 11.x through 11.1.7, update to version 11.1.8 or later.
For versions 12.x through 12.0.0, update to version 12.0.1 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helix Mobile Server
Helix Server