CVE-2000-0474: High severity realnetworks realserver vulnerability
Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
RealNetworks RealServerfrom your environment.Uninstall RealNetworks RealServer if the service is not required in order to eliminate exposure to the vulnerability.
- Configuration
Disable the viewsource directory/feature in the RealServer configuration or restrict its access so it is not reachable by remote clients. If no explicit setting exists, remove or deny access to the viewsource directory from the served content.
RealNetworks RealServer viewsource directory access = disabled or restricted - Compensating control
Block or filter requests targeting the 'viewsource' path (or equivalent resource) at the network perimeter (firewall, reverse proxy, or WAF) to prevent remote clients from reaching the vulnerable RealServer endpoint.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0474?
CVE-2000-0474 is classified as a denial of service vulnerability.
How do I fix CVE-2000-0474?
To mitigate CVE-2000-0474, it is recommended to upgrade Real Networks RealServer to a version that is not affected, specifically versions after 8.0_beta.
What versions of RealServer are affected by CVE-2000-0474?
CVE-2000-0474 affects RealServer versions 7.0, 7.0.1, and 8.0_beta.
Can CVE-2000-0474 be exploited remotely?
Yes, CVE-2000-0474 can be exploited remotely via malformed requests from attackers.
Is there any exploit code available for CVE-2000-0474?
Information about exploit code for CVE-2000-0474 may exist in security forums, but it is not officially disclosed.