RealNetworks Helix Server 'RTSP' Remote Denial of Service Vulnerability
BID:35731
Info
RealNetworks Helix Server 'RTSP' Remote Denial of Service Vulnerability
| Bugtraq ID: | 35731 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-2533 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2009 12:00AM |
| Updated: | Jul 20 2009 04:26PM |
| Credit: | Damian Frizza from Core Security Technologies |
| Vulnerable: |
RealNetworks Helix Server 12.0.1 .215 RealNetworks Helix Server 12.0.1 RealNetworks Helix Server 12.0 RealNetworks Helix Server 11.1.8 RealNetworks Helix Server 11.1.7 RealNetworks Helix Server 11.1.6 RealNetworks Helix Server 11.1.4 RealNetworks Helix Server 11.1.2 RealNetworks Helix Mobile Server 12.0.1 .215 RealNetworks Helix Mobile Server 12.0.1 RealNetworks Helix Mobile Server 12.0 RealNetworks Helix Mobile Server 11.1.8 RealNetworks Helix Mobile Server 11.1.7 RealNetworks Helix Mobile Server 11.1.6 RealNetworks Helix Mobile Server 11.1.4 RealNetworks Helix Mobile Server 11.1.2 |
| Not Vulnerable: |
RealNetworks Helix Server 13.0 RealNetworks Helix Mobile Server 13.0 |
Discussion
RealNetworks Helix Server 'RTSP' Remote Denial of Service Vulnerability
RealNetworks Helix Server is prone to a remote denial-of-service vulnerability because the application fails to properly handle invalid requests.
Exploiting this issue allows remote attackers to cause the application to crash, effectively denying service to legitimate users.
These issues affect versions prior to Helix Server and Helix Mobile Server 13.0.0.
RealNetworks Helix Server is prone to a remote denial-of-service vulnerability because the application fails to properly handle invalid requests.
Exploiting this issue allows remote attackers to cause the application to crash, effectively denying service to legitimate users.
These issues affect versions prior to Helix Server and Helix Mobile Server 13.0.0.
Exploit / POC
RealNetworks Helix Server 'RTSP' Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
RealNetworks Helix Server 'RTSP' Remote Denial of Service Vulnerability
Solution:
Updates are available; please see the references for details.
Solution:
Updates are available; please see the references for details.
References
RealNetworks Helix Server 'RTSP' Remote Denial of Service Vulnerability
References:
References:
- Real Networks Helix Server Homepage (Real Networks)
- CORE-2009-0227 Real Helix DNA RTSP and SETUP request handler vulnerabilities (CORE Security Technologies)
- RealNetworks Security Update 071409HS (Real Networks)