20030825 New Bug in RealServermailing list
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0087.html CVE-2003-0725
Real Server 7/8/9 (Windows / Linux) - Remote Code Execution
Record summary
CVE-2003-0725 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBReal Server 7/8/9 (Windows / Linux) - Remote Code ExecutionExploitDB exploitby Johnny CyberpunkNot analyzed1 file
References
6lists.immunitysec.com
http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html VU#934932Third-party advisory
http://www.kb.cert.org/vuls/id/934932 8476vdb entry
http://www.securityfocus.com/bid/8476 service.real.comConfirmation
http://www.service.real.com/help/faq/security/rootexploit082203.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0725