RealNetworks Zips Up the Helix

RealNetworks Zips Up the Helix

Written By
Dennis Fisher
Dennis Fisher
Dec 20, 2002
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

RealNetworks Inc. has issued a patch for three newly discovered vulnerabilities in its Helix Universal Server media delivery software. The vulnerabilities, all buffer overruns, could enable an attacker to run code on remote machines.

All of the flaws affect version 9.0 of the server running on all of the available platforms. Its unknown whether any previous versions are vulnerable.

While they are all buffer overruns, each vulnerability has a different attack method. The first flaw can be exploited by sending a large character string to the Transport field within a particular GET request. The attackers code would then overwrite the saved return address and run with system privileges.

The second vulnerability requires an attacker to send an overly long URL to the Describe field. Again, the attackers code would overwrite the saved return address and execute.

In order to exploit the third flaw, an attacker would need to make two simultaneous HTTP requests. This, too, would result in the execution of the attackers code, according to a bulletin on the vulnerabilities released Friday by Next Generation Security Software Ltd., which discovered the issues.

The Helix Universal Server is a back-end system designed to deliver thousands of concurrent audio streams. Its widely used by companies that host webcasts and other online events.

The patch for the vulnerabilities is available here.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.