CVE-2009-2534: Input Validation
Published Jul 20, 2009
·Updated
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.
Affected Software
5 affected components
RealNetworks Helix Server<=12.0.1
RealNetworks Helix Server=11.0
RealNetworks Helix Server=12.0.0
RealNetworks Helix Server Mobile<=12.0.0
RealNetworks Helix Server Mobile=11.0
Event History
Jul 20, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2534?
CVE-2009-2534 is a high-severity vulnerability that can cause denial of service due to a daemon crash.
2
How do I fix CVE-2009-2534?
To fix CVE-2009-2534, you should update your Helix Server or Helix Mobile Server to version 13.0.0 or later.
3
Which versions of Helix Server are affected by CVE-2009-2534?
CVE-2009-2534 affects Helix Server versions up to 12.0.1 and Helix Server Mobile versions up to 12.0.0.
4
Can CVE-2009-2534 be exploited remotely?
Yes, CVE-2009-2534 can be exploited remotely through malicious RTSP SETUP requests.
5
What type of attack is possible with CVE-2009-2534?
CVE-2009-2534 allows attackers to trigger a denial of service attack by causing the server daemon to crash.