RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17648
http://www.idefense.com/application/poi/display?id=151&type=vulnerabilities