Short Name |
RTSP:REALSERVER:REAL-SETUP-OF1 |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
RTSP |
Keywords |
real realnetworks realserver setup overflow rtsp |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against the RealServer daemon running on Microsoft Windows 2000. RealNetworks RealServer versions 8.0.2 and earlier are vulnerable. Attackers can send a SETUP command to the RealServer daemon and overflow the buffer to gain administrator access to the server.
RealNetworks has reported that buffer overflow vulnerabilities exist in Helix Universal Server/RealServer versions 8.01 and earlier. This is due to insufficient bounds checking of URIs by RTSP methods. Successful exploitation of these issues may result in execution of malicious instructions in the security context of the server process. The issues were reported on Microsoft Windows platforms but also may also affect other platforms. This issue may be related to previously reported issues (BID 6454, BID 6456 and BID 6458).