RealNetworks Helix Universal Server and RealServer contain a flaw that may allow a remote attacker to execute arbitrary code. The issue is due to the server not properly handling multiple simultaneous HTTP GET requests. If an attacker sends two specially crafted requests it will overflow a buffer allowing execution of arbitrary code with the privileges of the server.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Upgrade to version 9.01 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.