CVE-2009-2533: Input Validation
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SETPARAMETER requests with empty DataConvertBuffer headers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2533?
CVE-2009-2533 is classified as a denial of service vulnerability due to its potential to cause a daemon exit.
How do I fix CVE-2009-2533?
To remediate CVE-2009-2533, users should upgrade to Helix Server version 13.0.0 or later.
What versions are affected by CVE-2009-2533?
CVE-2009-2533 affects RealNetworks Helix Server versions prior to 13.0.0 and Helix Mobile Server versions prior to 12.0.1.
Can CVE-2009-2533 be exploited remotely?
Yes, CVE-2009-2533 can be exploited remotely through RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.
What impact does CVE-2009-2533 have on system availability?
CVE-2009-2533 can lead to a denial of service condition, affecting the availability of the Helix Server and Helix Mobile Server.