CVE-2003-0725

RealNetworks Helix Universal Server <9 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0725. PoCs published by Johnny Cyberpunk.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in RealServer 8+9 via a maliciously crafted RTSP request. It includes shellcode for both Windows and Linux to achieve remote code execution.

Description

Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Johnny Cyberpunk · cremotemultiple
https://www.exploit-db.com/exploits/86

This exploit targets a buffer overflow vulnerability in RealServer 8+9 via a maliciously crafted RTSP request. It includes shellcode for both Windows and Linux to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RealServer 8+9
No auth needed
Prerequisites: Network access to the target's RTSP port (554)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/934932
Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0087.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8476

Scores

EPSS 0.5125
EPSS Percentile 98.8%

Details

Status published
Products (12)
realnetworks/helix_universal_server 8.0.1
realnetworks/helix_universal_server 9.0
realnetworks/helix_universal_server 9.0.1
realnetworks/helix_universal_server 9.0.2.794
realnetworks/realserver 7.0
realnetworks/realserver 7.0.1
realnetworks/realserver 7.0.2
realnetworks/realserver 8.0
realnetworks/realserver 8.0.1
realnetworks/realserver 8.0.2
... and 2 more
Published Oct 20, 2003
Tracked Since Feb 18, 2026