CVE-2006-3276: Buffer Overflow
Published Jun 28, 2006
·Updated
Heap-based buffer overflow in RealNetworks Helix DNA Server 10.0 and 11.0 allows remote attackers to execute arbitrary code via (1) a long User-Agent HTTP header in the RTSP service and (2) unspecified vectors involving the "parsing of HTTP URL schemes".
Affected Software
2 affected components
RealNetworks Helix DNA Server=10.0
RealNetworks Helix DNA Server=11.0
Remediation
Patch Available
Event History
Jun 28, 2006
CVE Published
10:05 PM
Jun 29, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3276?
CVE-2006-3276 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-3276?
To resolve CVE-2006-3276, upgrade RealNetworks Helix DNA Server to version 11.1 or later.
3
What software is affected by CVE-2006-3276?
CVE-2006-3276 affects RealNetworks Helix DNA Server versions 10.0 and 11.0.
4
What type of vulnerability is CVE-2006-3276?
CVE-2006-3276 is a heap-based buffer overflow vulnerability.
5
Can CVE-2006-3276 be exploited remotely?
Yes, CVE-2006-3276 can be exploited remotely through crafted User-Agent HTTP headers.