PT-2010-3023 · Realnetworks · Helix Mobile Server+2

Published

2010-04-20

·

Updated

2010-12-29

·

CVE-2010-1319

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AgentX++ version 1.4.16 RealNetworks Helix Server versions 11.x through 13.x RealNetworks Helix Mobile Server versions 11.x through 13.x
Description The issue is caused by an integer overflow in the AgentX::receive agentx function, which allows remote attackers to execute arbitrary code via a request with a crafted payload length.
Recommendations For AgentX++ version 1.4.16, update to a version that fixes the integer overflow issue in the AgentX::receive agentx function. For RealNetworks Helix Server versions 11.x through 13.x, update to a version that fixes the integer overflow issue in the AgentX::receive agentx function. For RealNetworks Helix Mobile Server versions 11.x through 13.x, update to a version that fixes the integer overflow issue in the AgentX::receive agentx function.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1319

Affected Products

Agentx++
Helix Mobile Server
Helix Server