Vulnerability record · CVE-2002-1643 · published 19 December 2002
CVE-2002-1643: RealNetworks Helix Universal Server RTSP/HTTP buffer overflows allow remote code execution
RRealnetworks · Helix Universal Server
RealNetworks Helix Universal Server 9.0 (9.0.2.768) contains multiple buffer overflows reachable over the network. A long Transport field in a SETUP RTSP request, a DESCRIBE RTSP request with a long URL argument, or two simultaneous HTTP GET requests with long arguments can overflow buffers. The flaw matters because it permits unauthenticated remote code execution against a media streaming server.
Description
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is legacy and not in KEV.
What it is
RealNetworks Helix Universal Server 9.0 (9.0.2.768) contains multiple buffer overflows reachable over the network. A long Transport field in a SETUP RTSP request, a DESCRIBE RTSP request with a long URL argument, or two simultaneous HTTP GET requests with long arguments can overflow buffers. The flaw matters because it permits unauthenticated remote code execution against a media streaming server.
Impact
An attacker can execute arbitrary code with the privileges of the Helix Universal Server process, potentially leading to full compromise of the host. No privilege escalation or local access is required beyond network reachability.
Attack surface
Reached over the network via RTSP (SETUP, DESCRIBE) and HTTP requests to the server's listening ports. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.747 (99.5th percentile) and one reference is tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Apply the vendor patch referenced in the RealNetworks security advisory and CERT/CC VU#974689.
- Upgrade to a fixed Helix Universal Server version if the 9.0.2.768 build is still in use.
- Restrict network access to RTSP and HTTP management/streaming ports to trusted sources only.
- Monitor vendor advisories for any further updates, as the product is legacy and may be unsupported.
Detection
- Inspect RTSP traffic for SETUP requests with abnormally long Transport headers or DESCRIBE requests with unusually long URL arguments.
- Look for pairs of simultaneous HTTP GET requests containing long arguments to the Helix server.
- Monitor server process crashes or unexpected restarts that could indicate failed overflow attempts.
- Review network logs for scanning or exploit traffic targeting RTSP (typically TCP 554) and HTTP ports on Helix hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1643 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.