Junglewise Threat Intelligence

CVE-1999-1045: RealNetworks RealServer denial of service in pnserver

CVE-1999-1045 · Severity: high · CVSS 7.8 · Published 1998-01-15

Executive brief

RealServer (formerly Progressive Networks RealServer) is a media streaming server used to deliver audio and video content. A vulnerability in the server's handling of incoming requests allows a remote attacker to crash the service by sending a small amount of malformed data. This results in a denial of service, preventing legitimate users from accessing hosted media streams.

Technical details

The pnserver daemon in RealServer (versions 4.0 through 5.0) contains a vulnerability, likely a buffer overflow, in its request processing logic. An unauthenticated remote attacker can trigger a service crash by connecting to the default port (typically 7070) and sending a short sequence of malformed characters or a large volume of text that exceeds internal buffer limits. Specifically, certain telnet-style control characters or long strings in the initial connection phase can cause the daemon to terminate. The issue affects both Unix (Solaris) and Windows NT platforms. A patch was released in version 5.01 to address this flaw.

Affected products

  • RealNetworks (Progressive Networks) RealServer 5.0 and earlier

Timeline

  • 1998-01-15: disclosed: Public disclosure via Rootshell Security Bulletin #7 and Bugtraq
  • 1998-01-15: advisory: NVD publication date
  • 1998-08-17: patched: Confirmation of patches available in version 5.01

References