Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.
2009-01-20T16:00:00.203
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | realnetworks | helix_server | 11.0 | Yes |
Application | realnetworks | helix_server | 12.0.0 | Yes |
Application | realnetworks | helix_server_mobile | 11.0 | Yes |
Application | realnetworks | helix_server_mobile | 12.0.0 | Yes |