RealNetworks Helix Server 11.x / 12.x / 13.x Multiple Vulnerabilities

Critical Nessus Network Monitor Plugin ID 5511

Synopsis

The remote media streaming server is affected by multiple vulnerabilities.

Description

According to its banner, the remote host is running version 11.x, 12.x, or 13.x of RealNetworks Helix Server / Helix Mobile Server. Such versions are potentially affected by multiple vulnerabilities.

- A heap overflow exists in the NTLM authentication code related to invalid Base64 encoding. (CVE-2010-1317)

- A stack-based buffer overflow within AgentX++ could lead to arbitrary code execution. (CVE-2010-1318)

- An integer overflow within AgentX++ could lead to arbitrary code execution. (CVE-2010-1319)

Solution

Upgrade to RealNetworks Helix Server / Helix Mobile Server 14.0.0 or later.

See Also

http://www.nessus.org/u?d5d74423

Plugin Details

Severity: Critical

ID: 5511

Family: Generic

Published: 2010/04/15

Modified: 2016/01/19

Nessus ID: 45543

Risk Information

Risk Factor: Critical

CVSSv2

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSSv3

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

Patch Publication Date: 2010/04/15

Vulnerability Publication Date: 2010/04/15

Exploitable With

Core Impact

Metasploit (AgentX++ Master AgentX::receive_agentx Stack Buffer Overflow)

Reference Information

CVE: CVE-2010-1317, CVE-2010-1318, CVE-2010-1319

BID: 39490, 39561, 39564