CVE-2000-0272: High severity realnetworks realserver vulnerability
RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
RealNetworks RealServerfrom your environment.Uninstall RealNetworks RealServer if the product is not required to eliminate exposure to malformed-input denial-of-service on port 7070.
- Configuration
Reconfigure RealServer to stop listening on TCP port 7070 for external connections (disable the service on that port or bind it to localhost) to prevent remote malformed-input attacks.
RealNetworks RealServer listen_port (7070) = disabled or bound to localhost - Compensating control
Block or restrict TCP port 7070 at network perimeter and host-based firewalls. If the service is required, allow access only from trusted management IPs or networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0272?
CVE-2000-0272 is categorized as a denial of service vulnerability.
How do I fix CVE-2000-0272?
To mitigate CVE-2000-0272, it is recommended to update the RealNetworks RealServer to the latest version that addresses this vulnerability.
What software versions are affected by CVE-2000-0272?
CVE-2000-0272 affects various versions of RealNetworks RealServer including basic, g2_1.0, plus, pro, and intranet editions.
Can CVE-2000-0272 be exploited remotely?
Yes, CVE-2000-0272 can be exploited remotely by sending malformed input to the RealServer at port 7070.
What impact does CVE-2000-0272 have on the system?
The impact of CVE-2000-0272 results in a denial of service, causing the server to become unresponsive.