CVE-2006-6026

Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request that contains an invalid LoadTestPassword field.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:realnetworks:helix_dna_server:11.0:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:helix_dna_server:11.1:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:helix_mobile_server:*:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:helix_server:*:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:helix_server:11.0:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:helix_server:11.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:21

Type Values Removed Values Added
References () http://docs.real.com/docs/security/SecurityUpdate032107Server.pdf - () http://docs.real.com/docs/security/SecurityUpdate032107Server.pdf -
References () http://gleg.net/helix.txt - () http://gleg.net/helix.txt -
References () http://lists.helixcommunity.org/pipermail/server-cvs/2007-January/003783.html - () http://lists.helixcommunity.org/pipermail/server-cvs/2007-January/003783.html -
References () http://secunia.com/advisories/22944 - Vendor Advisory () http://secunia.com/advisories/22944 - Vendor Advisory
References () http://web.archive.org/web/20060502082622/www.gleg.net/vulndisco_pack_professional.shtml - () http://web.archive.org/web/20060502082622/www.gleg.net/vulndisco_pack_professional.shtml -
References () http://www.attrition.org/pipermail/vim/2007-March/001459.html - () http://www.attrition.org/pipermail/vim/2007-March/001459.html -
References () http://www.attrition.org/pipermail/vim/2007-March/001468.html - () http://www.attrition.org/pipermail/vim/2007-March/001468.html -
References () http://www.securityfocus.com/archive/1/463333/100/0/threaded - () http://www.securityfocus.com/archive/1/463333/100/0/threaded -
References () http://www.securityfocus.com/bid/21141 - () http://www.securityfocus.com/bid/21141 -
References () http://www.securityfocus.com/bid/23068 - () http://www.securityfocus.com/bid/23068 -
References () http://www.vupen.com/english/advisories/2007/1056 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/1056 - Vendor Advisory
References () https://www.exploit-db.com/exploits/3531 - () https://www.exploit-db.com/exploits/3531 -

Information

Published : 2006-11-21 23:07

Updated : 2024-11-21 00:21


NVD link : CVE-2006-6026

Mitre link : CVE-2006-6026

CVE.ORG link : CVE-2006-6026


JSON object : View

Products Affected

realnetworks

  • helix_server
  • helix_mobile_server
  • helix_dna_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer