Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/304203 | Vendor Advisory |
http://www.nextgenss.com/advisories/realhelix.txt | Vendor Advisory |
http://www.service.real.com/help/faq/security/bufferoverrun12192002.html | Patch |
http://www.kb.cert.org/vuls/id/974689 | Patch Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/6454 | Exploit Patch |
http://www.securityfocus.com/bid/6456 | Patch |
http://www.securityfocus.com/bid/6458 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10917 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10916 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10915 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-12-18 21:00
Updated : 2017-12-22 18:29
NVD link : CVE-2002-1643
Mitre link : CVE-2002-1643
JSON object : View
CWE
Products Affected
realnetworks
- helix_universal_server