Multiple Vendors AgentX Receive Agentx Stack Buffer Overflow
Publish Date: 04 de lutego de 2011
Severity: : Critical
CVE Kennungen: : CVE-2010-1318
Advisory Date: 04 de lutego de 2011
DESCRIPTION
Stack-based buffer overflow in the AgentX::receive agentx function in AgentX 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.
INFORMATION EXPOSURE
Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.
AFFECTED SOFTWARE AND VERSION:
- Realnetworks Helix Mobile Server 13.1.1
- Realnetworks Helix Server 11.0
- Realnetworks Helix Server 11.1
- Realnetworks Helix Server 12.0.0
- Realnetworks Helix Server 12.0.1
- Realnetworks Helix Server 13.1.1
- Realnetworks Helix Server Mobile 11.0
- Realnetworks Helix Server Mobile 12.0.0
- Realnetworks Helix Server Mobile 13.0.0