CVE-2008-5911

N/A Unknown
Published: January 20, 2009 Modified: April 23, 2026
View on NVD

Description

Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/33360
Source: cve@mitre.org
Vendor Advisory
http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/33360
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securitytracker.com/id?1021498
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1021499
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1021500
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1021501
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/3521
Source: af854a3a-2127-422b-91ae-364da2661108

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
16.4%
95th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

realnetworks