« Volver al listado

CVE-2008-5911

Estado: ModificadaAlta (10)—

Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5911",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-01-20T16:00:00.203",
  "references": [
    {
      "url": "http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/33360",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1021498",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1021499",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1021500",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1021501",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/3521",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/33360",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1021498",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1021499",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1021500",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1021501",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/3521",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer en RealNetworks Helix Server y Helix Mobile Server v11.x anteriores a v11.1.8 y v12.x anteriores a v12.0.1 permite a atacantes remotos (1) provocar una denegación de servicio a través de tres comandos manipulados RTSP SETUP, o ejecutar código de su elección a través de (2) una petición de autenticación NTLM con datos malformados codificados en base64, (3) un comando RTSP DESCRIBE, o (4) una petición DataConvertBuffer."
    }
  ],
  "lastModified": "2026-06-16T23:01:12.690",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A30A2490-21FC-4C0D-80A3-B89E6F58E93A"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server:12.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0890EDD4-63FF-43EC-9EC4-852B34E00F51"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server_mobile:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74F01F2C-036C-4B6E-B66D-F0870801D397"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server_mobile:12.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CB773CC-C81C-424A-9493-4CAD2E0E8262"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "Per: http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf\r\n\r\nImpacted Products and Versions:\r\nHelix Server Version 11.x\r\nHelix Server Version 12.x\r\nHelix Mobile Server Version 11.x\r\nHelix Mobile Server Version 12.x",
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "Per: http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf\r\n\r\nThe Fix:\r\nVersion 11.1.8 and Version 12.0.1 of the Helix Server and the Helix Mobile Server have been updated to ensure that the above\r\nvulnerabilities have been resolved.\r\n\r\nSOLUTION:\r\nThe vulnerability is resolved on the following platforms by installing Version 11.1.8 or Version 12.0.1 of the Helix Server and the Helix\r\nMobile Server. This only pertains to supported versions of the platforms listed below. The updated version will be available on your\r\nRealNetworks PAM site after 11:59 p.m. PST, on December 15, 2008."
}