CVE-2008-5911
Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 6.19% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- realnetworks/helix server · realnetworks/helix server mobile
- Source
- cve@mitre.org
References
- http://docs.real.com/docs/security/SecurityUpdate121508HS.pdfVendor Advisory
- http://secunia.com/advisories/33360Vendor Advisory
- http://www.securitytracker.com/id?1021498
- http://www.securitytracker.com/id?1021499
- http://www.securitytracker.com/id?1021500
- http://www.securitytracker.com/id?1021501
- http://www.vupen.com/english/advisories/2008/3521
- http://docs.real.com/docs/security/SecurityUpdate121508HS.pdfVendor Advisory
- http://secunia.com/advisories/33360Vendor Advisory
- http://www.securitytracker.com/id?1021498
- http://www.securitytracker.com/id?1021499
- http://www.securitytracker.com/id?1021500
- http://www.securitytracker.com/id?1021501
- http://www.vupen.com/english/advisories/2008/3521
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.