Real Networks Helix Universal Server and RealServer contain a flaw that may allow a remote attacker to execute arbitrary code. The issue is due to a flaw in the RTSP DESCRIBE request handling that doesn't properly sanitize user input. If an attacker sends a specially crafted RTSP DESCRIBE request with an overly long URL they may be able to overflow a buffer and execute arbitrary code with the same privilege as the server.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Upgrade to version 9.01 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.