Real Networks Helix Universal Server Remote Buffer Overflow Vulnerability
BID:8476
Info
Real Networks Helix Universal Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 8476 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0725 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery of this vulnerability has been credited to Dave Aitel of Immunity, Inc. |
| Vulnerable: |
RealNetworks Real Server 8.0 Beta RealNetworks Real Server 8.0 2 RealNetworks Real Server 8.0 1 RealNetworks Real Server 8.0 RealNetworks Real Server 7.0.2 RealNetworks Real Server 7.0.1 RealNetworks Real Server 7.0 RealNetworks Real Server 6.0 x RealNetworks Real Server 5.0 RealNetworks Helix Universal Server 9.0.2 .794 RealNetworks Helix Universal Server 9.0 1 RealNetworks Helix Universal Server 9.0 RealNetworks Helix Universal Server 8.0 1 RealNetworks GameHouse dldisplay ActiveX control 0 |
| Not Vulnerable: |
RealNetworks Helix Universal Server 9.0.2 .802 |
Exploit / POC
Real Networks Helix Universal Server Remote Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit has been developed by Johnny Cyberpunk of TheHackersChoice (www.thc.org).
An exploit (realserver_describe_linux.pm) has been released as part of the MetaSploit Framework 2.0:
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit has been developed by Johnny Cyberpunk of TheHackersChoice (www.thc.org).
An exploit (realserver_describe_linux.pm) has been released as part of the MetaSploit Framework 2.0:
Solution / Fix
Real Networks Helix Universal Server Remote Buffer Overflow Vulnerability
Solution:
RealNetworks has released Helix Universal Server 9.0.2.802 to address this vulnerability. Users should contact the vendor to obtain upgrades.
Solution:
RealNetworks has released Helix Universal Server 9.0.2.802 to address this vulnerability. Users should contact the vendor to obtain upgrades.
References
Real Networks Helix Universal Server Remote Buffer Overflow Vulnerability
References:
References:
- My first IMPACT exploit (CORE Security)
- RealServer array overflow exploit (CORE Security)
- RealServer buffer overflow exploit (CORE Security)
- Server Exploit Fix (RealNetworks)
- Server Exploit Vulnerability (RealNetworks)