CVE-2000-0185: Medium severity realnetworks realserver vulnerability
RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
RealNetworks RealServer / RealNetworks RealSystem G2 Serverfrom your environment.If the product is not required, uninstall RealNetworks RealServer and RealSystem G2 Server to eliminate the information-leak risk.
- Compensating control
Prevent exposure of the server's real IP to untrusted networks by placing RealNetworks RealServer / RealSystem G2 Server behind a NAT, reverse proxy, or firewall and restricting access to trusted IP addresses only.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0185?
CVE-2000-0185 has a medium severity rating due to its potential exposure of the real IP address.
How do I fix CVE-2000-0185?
To fix CVE-2000-0185, update RealMedia RealServer to the latest version that addresses this vulnerability.
What systems are affected by CVE-2000-0185?
CVE-2000-0185 affects RealServer versions 5.0 and 7.0, as well as Realnetworks Realserver G2 version 1.0.
What type of vulnerability is CVE-2000-0185?
CVE-2000-0185 is a disclosure vulnerability that reveals private IP addresses.
Can CVE-2000-0185 be exploited remotely?
Yes, CVE-2000-0185 can be exploited remotely by an attacker to obtain private IP addresses.