what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

realHelix9.txt

realHelix9.txt
Posted Mar 18, 2004
Site pentest.co.uk

Pentest Limited Security Advisory - The RealNetworks Helix 9 Server allows for an authenticated attacker to submit malformed HTTP POST requests against the Administration server to trigger a buffer overflow and execute arbitrary code. Affected versions: Helix Universal Mobile Server and Gateway 10, version 10.1.1.120 and prior; Helix Universal Server and Gateway 9, version 9.0.2.881 and prior.

tags | advisory, web, overflow, arbitrary
advisories | CVE-2004-0049
SHA-256 | ec765fef32af92bfd91131b904f9e23f6d9eccca366c8270c0af828f68f1a4aa

realHelix9.txt

Change Mirror Download
Pentest Limited Security Advisory

RealNetworks Helix Server 9 Administration Server Buffer Overflow

Advisory Details
----------------
Title: RealNetworks Helix Server 9 Administration Server Buffer Overflow
Announcement date: 18 March 2004
Advisory Reference: ptl-2004-02
CVE Name: CAN-2004-0049
Products: Various RealNetworks Server Products (See Below)
Vulnerability Type : Buffer Overflow
Vendor-URL: http://www.realnetworks.com
Vendor-Status: Updated Version / Plugin Released
Remotely Exploitable: Yes (Authenticated User)
Locally Exploitable: Yes (Authenticated User)
Advisory URL: http://www.pentest.co.uk/

Vulnerability Description
--------------------------
Several of Real Networks Helix Server products utilise a common
Administration Interface which is available over HTTP and protected
by HTTP Basic Authentication.

An authenticated attacker can submit malformed HTTP POST
requests to the server's Administration interface, triggering a buffer
overflow and executing arbitrary code on the server.

On Windows platforms where the Helix Server is run as an NT Service,
this allows arbitrary code execution under the context of the NT SYSTEM
account.

It should be noted that the Server does not have a default username
and password - these are set during installation. In addition to this,
the Server runs on a random TCP port, configured during installation.

Vulnerable Versions
--------------------
Helix Universal Mobile Server & Gateway 10, version 10.1.1.120 and prior
Helix Universal Server and Gateway 9, version 9.0.2.881 and prior

RealSystem Server and Proxy version 8.x and earlier are not vulnerable

Whilst Windows 2000 was the only platform tested and confirmed to be
exploitable by Pentest Limited, the vendor advisory indicates that
multiple platforms are affected by this vulnerability including
Solaris, Linux, AIX, and FreeBSD.

Vendor Status
--------------
Real Networks:
05-01-2004 - Initial Pentest Limited Notification
06-01-2004 - Notification acknowledged by Real Networks
08-01-2004 - Draft Advisory sent to Pentest Limited By Real Networks
12-01-2004 - Initial Advisory published by Real Networks stating the
impact as 'Denial of Service'
26-02-2004 - Real Advisory updated to describe impact as 'potential root
exploit'
18-03-2004 - Pentest Limited Advisory released.

Fix
---
Updated versions of Helix Universal Server and Gateway 9 are available
from RealNetworks.

Updated Administration System plug-ins are available.

Further details are available in the RealNetworks advisory, available
at:

http://service.real.com/help/faq/security/security022604.html

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close