RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities

BID:33059

Info

RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities

Bugtraq ID: 33059
Class: Boundary Condition Error
CVE: CVE-2008-5911
Remote: Yes
Local: No
Published: Dec 16 2008 12:00AM
Updated: Jan 23 2009 06:12PM
Credit: TippingPoint and Noam Rathaus
Vulnerable: RealNetworks Helix Server 12.0
RealNetworks Helix Server 11.1.7
RealNetworks Helix Server 11.1.6
RealNetworks Helix Server 11.1.4
RealNetworks Helix Server 11.1.2
RealNetworks Helix Mobile Server 12.0
RealNetworks Helix Mobile Server 11.1.7
RealNetworks Helix Mobile Server 11.1.6
RealNetworks Helix Mobile Server 11.1.4
RealNetworks Helix Mobile Server 11.1.2
Not Vulnerable: RealNetworks Helix Server 12.0.1
RealNetworks Helix Server 11.1.8
RealNetworks Helix Mobile Server 12.0.1
RealNetworks Helix Mobile Server 11.1.8

Discussion

RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities

RealNetworks Helix Server is prone to multiple buffer-overflow vulnerabilities that can allow attackers to execute remote code.

Exploiting these issues may allow attackers to gain unauthorized access to affected computers. Failed attempts may cause crashes and deny service to legitimate users of the application.

These issues affect versions prior to Helix Server and Helix Mobile Server 11.1.8 and 12.0.1.

Exploit / POC

RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities

A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service for the Base64 NTLM authentication data issue. This exploit is not otherwise publicly available or known to be circulating in the wild.

Solution / Fix

RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities

Solution:
The vendor released Helix Server and Helix Mobile Server 11.1.8 and 12.0.1 to address these issues. Please see the references for more information.

References

RealNetworks Helix Server Multiple Remote Code Execution Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report