Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability
BID:9421
Info
Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability
| Bugtraq ID: | 9421 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2004 12:00AM |
| Updated: | Jan 14 2004 12:00AM |
| Credit: | Discovery credited to Matt Moore from Pentest Limited. |
| Vulnerable: |
RealNetworks Helix Universal Server 9.0.2 .881 RealNetworks Helix Universal Server 9.0.2 .802 RealNetworks Helix Universal Server 9.0.2 .794 RealNetworks Helix Universal Server 9.0 1 RealNetworks Helix Universal Server 9.0 RealNetworks Helix Universal Mobile Server 10.1.1 .120 RealNetworks Helix Universal Mobile Gateway 10.1.1 .120 RealNetworks Helix Universal Gateway 9.0.2 .881 RealNetworks Helix Universal Gateway 9.0 |
| Not Vulnerable: | |
Discussion
Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability
A problem has been identified in the handling of HTTP post requests in Real Networks Helix Universal Server. Because of this, a remote attacker may potentially compromise systems remotely if they possess legitimate credentials.
In addition to the Helix Universal Server, this problem is known to affect the Helix Universal Gateway, Helix Universal Mobile Server, and Helix Universal Mobile Gateway. This issue affects multiple platforms, including Windows, HP-UX, Solaris, AIX, Linux and Tru64.
A problem has been identified in the handling of HTTP post requests in Real Networks Helix Universal Server. Because of this, a remote attacker may potentially compromise systems remotely if they possess legitimate credentials.
In addition to the Helix Universal Server, this problem is known to affect the Helix Universal Gateway, Helix Universal Mobile Server, and Helix Universal Mobile Gateway. This issue affects multiple platforms, including Windows, HP-UX, Solaris, AIX, Linux and Tru64.
Exploit / POC
Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability
Solution:
Real has made fixes available for this issue. See the referenced Real Networks "Potential Server/Proxy Exploit Vulnerability - Update" bulletin for updated information on available fixes. Updated versions of the adminfs.so plug-in for various platforms are available to address this issue and are also listed in the referenced bulletin.
Solution:
Real has made fixes available for this issue. See the referenced Real Networks "Potential Server/Proxy Exploit Vulnerability - Update" bulletin for updated information on available fixes. Updated versions of the adminfs.so plug-in for various platforms are available to address this issue and are also listed in the referenced bulletin.
References
Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability
References:
References:
- Potential Server/Proxy Denial-of-Service Vulnerability (Real Networks)
- Potential Server/Proxy Exploit Vulnerability - Update (Real Networks)
- RealNetworks Helix Server 9 Administration Server Buffer Overflow (Pentest Limited)