RTSP: RealNetworks Helix Server rn5auth Credential Parsing Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the RealNetworks Helix Server. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the application.

Extended Description

RealNetworks Helix Server is prone to multiple remote vulnerabilities. Attackers can exploit theses issues to execute arbitrary code within the context of the affected application, cause denial-of service conditions, retrieve potentially sensitive information, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and steal cookie-based authentication credentials. RealNetworks Helix Server 14.2.0.212 is vulnerable; other versions may also be affected.

Affected Products

Real_networks helix_server

References

BugTraq: 52929

CVE: CVE-2012-0942

Short Name
RTSP:HELIX-RN5AUTH
Severity
Major
Recommended
False
Recommended Action
Drop
Category
RTSP
Keywords
Buffer CVE-2012-0942 Credential Helix Overflow Parsing RealNetworks Server bid:52929 rn5auth
Release Date
01/07/2013
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3434
False Positive
Unknown
Vendors

Real_networks

CVSS Score

7.5

Found a potential security threat?