RealNetworks Helix and Helix Mobile Server 'RTSP' Stack Buffer Overflow Vulnerability
BID:47109
Info
RealNetworks Helix and Helix Mobile Server 'RTSP' Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 47109 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-4596 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2011 12:00AM |
| Updated: | Mar 31 2011 12:00AM |
| Credit: | defrost via iDefense |
| Vulnerable: |
Real Networks Helix Server 13.0 Real Networks Helix Server 12.0.1 .215 Real Networks Helix Server 12.0.1 Real Networks Helix Server 12.0 Real Networks Helix Server 11.1.8 Real Networks Helix Server 11.1.7 Real Networks Helix Server 11.1.6 Real Networks Helix Server 11.1.4 Real Networks Helix Server 11.1.2 Real Networks Helix Server 14.0 Real Networks Helix Mobile Server 13.0 Real Networks Helix Mobile Server 12.0.1 .215 Real Networks Helix Mobile Server 12.0.1 Real Networks Helix Mobile Server 12.0 Real Networks Helix Mobile Server 11.1.8 Real Networks Helix Mobile Server 11.1.7 Real Networks Helix Mobile Server 11.1.6 Real Networks Helix Mobile Server 11.1.4 Real Networks Helix Mobile Server 11.1.2 Real Networks Helix Mobile Server 14.0 |
| Not Vulnerable: |
Real Networks Helix Server 14.2 Real Networks Helix Mobile Server 14.2 |
Discussion
RealNetworks Helix and Helix Mobile Server 'RTSP' Stack Buffer Overflow Vulnerability
RealNetworks Helix Server and Helix Mobile Server are prone to a remote stack-based buffer-overflow vulnerability due to a failure to properly bounds-check user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects versions prior to Helix Server and Helix Mobile Server 14.2.
RealNetworks Helix Server and Helix Mobile Server are prone to a remote stack-based buffer-overflow vulnerability due to a failure to properly bounds-check user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects versions prior to Helix Server and Helix Mobile Server 14.2.
Exploit / POC
RealNetworks Helix and Helix Mobile Server 'RTSP' Stack Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RealNetworks Helix and Helix Mobile Server 'RTSP' Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RealNetworks Helix and Helix Mobile Server 'RTSP' Stack Buffer Overflow Vulnerability
References:
References:
- Real Networks Helix Server Homepage (Real Networks)
- RealNetworks Helix DNA Server RTSP Stack Buffer Overflow (iDefense)
- RealNetworks Security Update 033111HS (Real Networks)