Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/974689 | Patch Third Party Advisory US Government Resource |
http://www.nextgenss.com/advisories/realhelix.txt | Vendor Advisory |
http://www.securityfocus.com/archive/1/304203 | Vendor Advisory |
http://www.securityfocus.com/bid/6454 | Exploit Patch |
http://www.securityfocus.com/bid/6456 | Patch |
http://www.securityfocus.com/bid/6458 | Patch |
http://www.service.real.com/help/faq/security/bufferoverrun12192002.html | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10915 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10916 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10917 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2002-12-19 05:00
Updated : 2024-02-04 16:31
NVD link : CVE-2002-1643
Mitre link : CVE-2002-1643
CVE.ORG link : CVE-2002-1643
JSON object : View
Products Affected
realnetworks
- helix_universal_server
CWE