Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability

BID:9421

Info

Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability

Bugtraq ID: 9421
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Jan 14 2004 12:00AM
Updated: Jan 14 2004 12:00AM
Credit: Discovery credited to Matt Moore from Pentest Limited.
Vulnerable: RealNetworks Helix Universal Server 9.0.2 .881
RealNetworks Helix Universal Server 9.0.2 .802
RealNetworks Helix Universal Server 9.0.2 .794
RealNetworks Helix Universal Server 9.0 1
RealNetworks Helix Universal Server 9.0
RealNetworks Helix Universal Mobile Server 10.1.1 .120
RealNetworks Helix Universal Mobile Gateway 10.1.1 .120
RealNetworks Helix Universal Gateway 9.0.2 .881
RealNetworks Helix Universal Gateway 9.0
Not Vulnerable:

Discussion

Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability

A problem has been identified in the handling of HTTP post requests in Real Networks Helix Universal Server. Because of this, a remote attacker may potentially compromise systems remotely if they possess legitimate credentials.

In addition to the Helix Universal Server, this problem is known to affect the Helix Universal Gateway, Helix Universal Mobile Server, and Helix Universal Mobile Gateway. This issue affects multiple platforms, including Windows, HP-UX, Solaris, AIX, Linux and Tru64.

Exploit / POC

Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability

Solution:
Real has made fixes available for this issue. See the referenced Real Networks "Potential Server/Proxy Exploit Vulnerability - Update" bulletin for updated information on available fixes. Updated versions of the adminfs.so plug-in for various platforms are available to address this issue and are also listed in the referenced bulletin.

References

Real Networks Helix Server/Gateway Administration Service HTTP Post System Compromise Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report