CVE-2000-0001: Medium severity realnetworks realserver vulnerability
RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
RealNetworks RealServerfrom your environment.If the RealServer component is not required, uninstall or take the RealMedia/RealServer service offline until a vendor-supplied fix is available.
- Compensating control
Restrict network access to the RealNetworks RealServer to trusted IPs (via firewall/ACLs) and/or place the server behind a WAF or reverse proxy that blocks or rate-limits excessively long 'ramgen' requests to mitigate remote DoS until a vendor patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0001?
CVE-2000-0001 is classified as a denial of service vulnerability which can disrupt server availability.
How do I fix CVE-2000-0001?
To fix CVE-2000-0001, you should update to a patched version of RealServer that addresses this specific denial of service issue.
What products are affected by CVE-2000-0001?
CVE-2000-0001 specifically affects RealServer 5.0.
Can CVE-2000-0001 be exploited remotely?
Yes, CVE-2000-0001 can be exploited remotely by sending a long ramgen request to the RealMedia server.
What type of attack is CVE-2000-0001 associated with?
CVE-2000-0001 is associated with a denial of service attack that can render the RealMedia server unresponsive.