← Vulnerability feed

Vulnerability record · CVE-2003-0725 · published 20 October 2003

CVE-2003-0725: RealNetworks Helix/RealServer RTSP parser buffer overflow

RRealnetworks · Helix Universal Server

The RTSP protocol parser in the View Source plug-in (vsrcplin.so / vsrcplin3260.dll) shipped with RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 contains a buffer overflow. A remote, unauthenticated attacker can trigger it through crafted RTSP input, and the flaw is serious because it can lead to arbitrary code execution on the server.

7.5 CVSS 2.0 High EPSS 49% · top 1.2%
7.5CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with a high EPSS score and a public exploit reference, though the product is legacy and no KEV listing exists.

What it is

The RTSP protocol parser in the View Source plug-in (vsrcplin.so / vsrcplin3260.dll) shipped with RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 contains a buffer overflow. A remote, unauthenticated attacker can trigger it through crafted RTSP input, and the flaw is serious because it can lead to arbitrary code execution on the server.

Impact

An attacker gains remote code execution in the context of the affected server process, which on these media servers typically runs with elevated privileges. That allows full compromise of the host rather than just a denial of service.

Attack surface

Reachable over the network via the RTSP service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The description does not specify the exact RTSP request or port, so the precise trigger is not documented in this record.

Exploitation

Not listed in CISA KEV, but EPSS is 0.48574 (98.8th percentile), indicating high predicted exploitation activity. A reference is tagged Exploit, so public exploit code is associated with this issue.

What to do

  • Apply the vendor patch referenced in the RealNetworks security advisory and SecurityFocus BID 8476; patch or decommission affected Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 installations.
  • If patching is not immediately possible, restrict RTSP access to trusted networks and block external access to the RTSP service.
  • Remove or disable the View Source plug-in (vsrcplin.so / vsrcplin3260.dll) where it is not required.
  • Run the media server with least privilege and isolate it from sensitive internal networks.
  • Monitor vendor and CERT/CC advisories for updated guidance on this legacy product.

Detection

  • Inspect RTSP request logs for unusually long or malformed request lines and headers targeting the media server.
  • Monitor for crashes or restarts of the Helix/RealServer process that coincide with RTSP traffic.
  • Watch for unexpected child processes or outbound connections spawned by the media server process.
  • Alert on exploit attempts matching public PoC patterns for this RTSP parser overflow.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0725 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2004-0774Realnetworks helix universal mobile server and gateway vulnerabilityRealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaus…EPSS 1.9%7.8CVE-2000-0474Realnetworks realserver vulnerabilityReal Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.EPSS 10%7.8CVE-2000-0272Realnetworks realserver vulnerabilityRealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.EPSS 10%7.8CVE-1999-1045Realnetworks realserver vulnerabilitypnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.EPSS 2.2%7.5CVE-2004-0389RealNetworks Helix Universal Server null dereference DoS via malformed RTSP requestsRealNetworks Helix Universal Server 9.0.1 and 9.0.2 crashes on malformed requests that trigger a null pointer dereference. The flaw is reachable over…EPSS 55%analysed7.5CVE-2002-1643RealNetworks Helix Universal Server RTSP/HTTP buffer overflows allow remote code executionRealNetworks Helix Universal Server 9.0 (9.0.2.768) contains multiple buffer overflows reachable over the network. A long Transport field in a SETUP …EPSS 75%analysed6.8CVE-2004-0049Realnetworks helix universal mobile server vulnerabilityHelix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Adminis…EPSS 1.5%5.0CVE-2000-1181Realnetworks realserver vulnerabilityReal Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive infor…EPSS 7.9%

Source: NIST National Vulnerability Database (record CVE-2003-0725), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.