Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.
| Software | From | Fixed in |
|---|---|---|
| realnetworks / helix_universal_server | 9.0.2.768 | 9.0.2.768.x |
| realnetworks / helix_universal_server | 9.0 | 9.0.x |