Short Name |
RTSP:OVERFLOW:TRANSPORT-OF |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
RTSP |
Keywords |
Real Server Transport Overflow |
Release Date |
2007/10/30 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Real Networks Real Server running on port 554. Windows and Linux versions of Real Server are vulnerable. Attackers can send an abnormally long RTSP TRANSPORT request to cause a server overflow and possibly execute arbitrary code.
Helix Universal Server is a multiple type media server distributed and maintained by RealNetworks. It is available for Unix, Linux, and Microsoft Windows platforms. A buffer overflow has been reported in the Helix Universal Server. Due to insufficient bounds checking on the 'describe' field of a RTSP request, it is possible for a user to exploit a boundry condition error. This could lead to the remote execution of arbitrary code with the privileges of the Helix Universal Server process.