Short Name |
APP:REAL:HELIX-URL-OF |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
RealNetworks Helix Universal Server URL Overflow |
Release Date |
2012/02/21 |
Update Number |
2085 |
Supported Platforms |
idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known flaw in RealNetworks Helix Server. A successful attack could result in arbitrary code execution.
Helix Universal Server is a multiple type media server distributed and maintained by RealNetworks. It is available for Unix, Linux, and Microsoft Windows platforms. A buffer overflow has been reported in the Helix Universal Server. Due to insufficient bounds checking, when the same long URI is requested via the HTTP server in two separate connections, a boundry condition error occurs. This could lead to the remote execution of arbitrary code with the privileges of the Helix Universal Server process.