RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.
References
Link | Resource |
---|---|
http://secunia.com/advisories/11395 | Broken Link Vendor Advisory |
http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities | Broken Link Exploit Patch Vendor Advisory |
http://www.securityfocus.com/bid/10157 | Broken Link Exploit Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15880 | Third Party Advisory VDB Entry |
http://secunia.com/advisories/11395 | Broken Link Vendor Advisory |
http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities | Broken Link Exploit Patch Vendor Advisory |
http://www.securityfocus.com/bid/10157 | Broken Link Exploit Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15880 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-06-01 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-0389
Mitre link : CVE-2004-0389
CVE.ORG link : CVE-2004-0389
JSON object : View
Products Affected
realnetworks
- helix_universal_server
CWE
CWE-476
NULL Pointer Dereference