RealServer 5.0 ramgen Denial of Service Vulnerability
BID:888
Info
RealServer 5.0 ramgen Denial of Service Vulnerability
| Bugtraq ID: | 888 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 23 1999 12:00AM |
| Updated: | Dec 23 1999 12:00AM |
| Credit: | Posted to Bugtraq by bow <[email protected]> on December 22, 1999. |
| Vulnerable: |
RealNetworks Real Server 5.0 |
| Not Vulnerable: |
RealNetworks Real Server 7.0 RealNetworks GameHouse dldisplay ActiveX control 0 |
Discussion
RealServer 5.0 ramgen Denial of Service Vulnerability
RealServer 5.0 can be crashed by sending an overly long (4082+ bytes) ramgen request. Regular functionality can be restored by restarting the RealServer software.
RealServer 5.0 can be crashed by sending an overly long (4082+ bytes) ramgen request. Regular functionality can be restored by restarting the RealServer software.
Exploit / POC
RealServer 5.0 ramgen Denial of Service Vulnerability
exploit available
exploit available
Solution / Fix
RealServer 5.0 ramgen Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Real Networks have made it clear that there are no plans to provide a patch for RealServer 5.0, although the issue has been resolved in newer releases.
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Real Networks have made it clear that there are no plans to provide a patch for RealServer 5.0, although the issue has been resolved in newer releases.