Real Server Administrator Port Buffer Overflow Vulnerability
BID:767
Info
Real Server Administrator Port Buffer Overflow Vulnerability
| Bugtraq ID: | 767 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 04 1999 12:00AM |
| Updated: | Nov 04 1999 12:00AM |
| Credit: | Discovered by dark spyrit <[email protected]> and posted to bugtraq on November 4, 1999. |
| Vulnerable: |
RealNetworks GameHouse dldisplay ActiveX control 0 |
| Not Vulnerable: | |
Discussion
Real Server Administrator Port Buffer Overflow Vulnerability
At installation, the Real Server software randomly selects an unused port as the remote administration port. This port is used by Real Server's remote web administration feature. To access this feature, the correct port must be specified and a valid username/password pair must be entered. By sending a long response to this authentication request, the buffer can be overwritten and arbitrary code can be executed on the server.
At installation, the Real Server software randomly selects an unused port as the remote administration port. This port is used by Real Server's remote web administration feature. To access this feature, the correct port must be specified and a valid username/password pair must be entered. By sending a long response to this authentication request, the buffer can be overwritten and arbitrary code can be executed on the server.
Exploit / POC
Real Server Administrator Port Buffer Overflow Vulnerability
These exploits will open a command prompt on port 6968. Will require tweaking for correct admin port and install directory (if different from the default).
realown.asm (Windows) by dark spyrit
rau.c (Unix) by Sebastian <[email protected]>
These exploits will open a command prompt on port 6968. Will require tweaking for correct admin port and install directory (if different from the default).
realown.asm (Windows) by dark spyrit
rau.c (Unix) by Sebastian <[email protected]>
Solution / Fix
Real Server Administrator Port Buffer Overflow Vulnerability
Solution:
Real Networks has released patches to adress this issue.
Windows NT:
http://docs.real.com/docs/g260authpatch/ppvb3260.dll
FreeBSD2:
http://docs.real.com/docs/g260authpatch/freebsd2/ppvbasic.so.6.0
FreeBSD3:
http://docs.real.com/docs/g260authpatch/freebsd3/ppvbasic.so.6.0
Irix 6.2:
http://docs.real.com/docs/g260authpatch/irix62/ppvbasic.so.6.0
Linux libc5:
http://docs.real.com/docs/g260authpatch/linux2/ppvbasic.so.6.0
Linux libc6:
http://docs.real.com/docs/g260authpatch/linuxc6/ppvbasic.so.6.0
Digital UNIX:
http://docs.real.com/docs/g260authpatch/osf4/ppvbasic.so.6.0
Solaris 2.51:
http://docs.real.com/docs/g260authpatch/solaris551/ppvbasic.so.6.0
Solaris 2.6:
http://docs.real.com/docs/g260authpatch/solaris56/ppvbasic.so.6.0
Solaris 2.7:
http://docs.real.com/docs/g260authpatch/solaris57/ppvbasic.so.6.0
Solution:
Real Networks has released patches to adress this issue.
Windows NT:
http://docs.real.com/docs/g260authpatch/ppvb3260.dll
FreeBSD2:
http://docs.real.com/docs/g260authpatch/freebsd2/ppvbasic.so.6.0
FreeBSD3:
http://docs.real.com/docs/g260authpatch/freebsd3/ppvbasic.so.6.0
Irix 6.2:
http://docs.real.com/docs/g260authpatch/irix62/ppvbasic.so.6.0
Linux libc5:
http://docs.real.com/docs/g260authpatch/linux2/ppvbasic.so.6.0
Linux libc6:
http://docs.real.com/docs/g260authpatch/linuxc6/ppvbasic.so.6.0
Digital UNIX:
http://docs.real.com/docs/g260authpatch/osf4/ppvbasic.so.6.0
Solaris 2.51:
http://docs.real.com/docs/g260authpatch/solaris551/ppvbasic.so.6.0
Solaris 2.6:
http://docs.real.com/docs/g260authpatch/solaris56/ppvbasic.so.6.0
Solaris 2.7:
http://docs.real.com/docs/g260authpatch/solaris57/ppvbasic.so.6.0
References
Real Server Administrator Port Buffer Overflow Vulnerability
References:
References:
- RealServer Security Update (Real Networks)