Executive brief
The Progressive Networks Real Video server, a platform used for streaming multimedia content, is susceptible to a remote crash. An attacker can exploit this vulnerability to shut down the streaming service, leading to a loss of availability for users and potential disruption of media broadcasts. This impact is limited to service availability and does not involve the theft of customer data.
Technical details
A denial of service vulnerability exists in the Progressive Networks Real Video server (pnserver). The flaw allows a remote, unauthenticated attacker to cause the server process to crash by sending specially crafted requests over the network. While the specific root cause (such as a buffer overflow or null pointer dereference) is not detailed in the legacy advisory, the attack vector is network-based and requires no user interaction. Successful exploitation results in a complete loss of availability for the streaming service until it is manually restarted.
Affected products
- Progressive Networks Real Video server (pnserver)
Timeline
- 1998-01-15: disclosed