RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities
BID:33059
Info
RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 33059 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-5911 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2008 12:00AM |
| Updated: | Jan 23 2009 06:12PM |
| Credit: | TippingPoint and Noam Rathaus |
| Vulnerable: |
RealNetworks Helix Server 12.0 RealNetworks Helix Server 11.1.7 RealNetworks Helix Server 11.1.6 RealNetworks Helix Server 11.1.4 RealNetworks Helix Server 11.1.2 RealNetworks Helix Mobile Server 12.0 RealNetworks Helix Mobile Server 11.1.7 RealNetworks Helix Mobile Server 11.1.6 RealNetworks Helix Mobile Server 11.1.4 RealNetworks Helix Mobile Server 11.1.2 |
| Not Vulnerable: |
RealNetworks Helix Server 12.0.1 RealNetworks Helix Server 11.1.8 RealNetworks Helix Mobile Server 12.0.1 RealNetworks Helix Mobile Server 11.1.8 |
Discussion
RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities
RealNetworks Helix Server is prone to multiple buffer-overflow vulnerabilities that can allow attackers to execute remote code.
Exploiting these issues may allow attackers to gain unauthorized access to affected computers. Failed attempts may cause crashes and deny service to legitimate users of the application.
These issues affect versions prior to Helix Server and Helix Mobile Server 11.1.8 and 12.0.1.
RealNetworks Helix Server is prone to multiple buffer-overflow vulnerabilities that can allow attackers to execute remote code.
Exploiting these issues may allow attackers to gain unauthorized access to affected computers. Failed attempts may cause crashes and deny service to legitimate users of the application.
These issues affect versions prior to Helix Server and Helix Mobile Server 11.1.8 and 12.0.1.
Exploit / POC
RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service for the Base64 NTLM authentication data issue. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service for the Base64 NTLM authentication data issue. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities
Solution:
The vendor released Helix Server and Helix Mobile Server 11.1.8 and 12.0.1 to address these issues. Please see the references for more information.
Solution:
The vendor released Helix Server and Helix Mobile Server 11.1.8 and 12.0.1 to address these issues. Please see the references for more information.
References
RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities
References:
References:
- Real Networks Helix Server Homepage (Real Networks)
- SecurityUpdate121508HS (Real Networks)