CVE-1999-1045: High severity realnetworks realserver vulnerability
pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
RealNetworks/RealServer (pnserver)from your environment.Uninstall RealServer or remove the pnserver component if it is not required.
- Configuration
Stop and disable the pnserver service on hosts running RealServer to prevent remote denial-of-service from short malformed requests.
RealServer (pnserver) service_enabled = false - Compensating control
Block or restrict network access to the pnserver service at the network perimeter or host firewall (restrict to trusted IPs) to limit exposure to remote attackers.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1045?
CVE-1999-1045 is rated as a denial of service vulnerability, allowing attackers to disrupt service.
How do I fix CVE-1999-1045?
The recommended fix for CVE-1999-1045 is to upgrade RealServer to a version later than 5.0.
What software versions are affected by CVE-1999-1045?
CVE-1999-1045 affects RealServer version 5.0 specifically.
What type of attack does CVE-1999-1045 allow?
CVE-1999-1045 allows remote attackers to execute denial of service attacks by sending malformed requests.
Is CVE-1999-1045 a critical vulnerability?
CVE-1999-1045 is not considered critical but poses a significant risk of service interruption.