5

CVE-2012-2268

master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than CVE-2012-1923.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Realnetworks ≫ Helix Server Version 14.0.0
Realnetworks ≫ Helix Server Version 14.0.1
Realnetworks ≫ Helix Server Version 14.2
Realnetworks ≫ Helix Server Version 14.2.0.212
Realnetworks ≫ Helix Mobile Server Version 14.0.0
Realnetworks ≫ Helix Mobile Server Version 14.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.721
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://helixproducts.real.com/docs/security/SecurityUpdate04022012HS.pdf
Vendor Advisory
http://www.securityfocus.com/bid/52929
http://www.securitytracker.com/id?1026898
http://secunia.com/secunia_research/2012-9/
Vendor Advisory