RealNetworks Helix Server 'x-wap-profile' Header Remote Code Execution Vulnerability
BID:47110
Info
RealNetworks Helix Server 'x-wap-profile' Header Remote Code Execution Vulnerability
| Bugtraq ID: | 47110 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-4235 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2011 12:00AM |
| Updated: | Apr 01 2011 08:35PM |
| Credit: | Defrost working with Tippingpoint�??s Zero Day Initiative and iDefense. |
| Vulnerable: |
Real Networks Helix Server 13.0 Real Networks Helix Server 12.0.1 .215 Real Networks Helix Server 12.0.1 Real Networks Helix Server 12.0 Real Networks Helix Server 14.0 Real Networks Helix Mobile Server 13.0 Real Networks Helix Mobile Server 12.0.1 .215 Real Networks Helix Mobile Server 12.0.1 Real Networks Helix Mobile Server 12.0 Real Networks Helix Mobile Server 14.0 |
| Not Vulnerable: |
Real Networks Helix Server 14.2 Real Networks Helix Mobile Server 14.2 |
Discussion
RealNetworks Helix Server 'x-wap-profile' Header Remote Code Execution Vulnerability
RealNetworks Helix Server is prone to a remote code-execution vulnerability because of a format-string error.
Successful exploits can allow the attacker to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
RealNetworks Helix Server is prone to a remote code-execution vulnerability because of a format-string error.
Successful exploits can allow the attacker to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
RealNetworks Helix Server 'x-wap-profile' Header Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RealNetworks Helix Server 'x-wap-profile' Header Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
RealNetworks Helix Server 'x-wap-profile' Header Remote Code Execution Vulnerability
References:
References:
- Real Networks Helix Server Homepage (Real Networks)
- ZDI-11-114 RealNetworks Helix Server x-wap-profile Format String Remote Code Exe (TippingPoint Zero Day Initiative)
- RealNetworks Security Update 033111HS (Real Networks)