RealNetworks RealPlayer URI Processing Buffer Overrun Vulnerability
BID:10527
Info
RealNetworks RealPlayer URI Processing Buffer Overrun Vulnerability
| Bugtraq ID: | 10527 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2004 12:00AM |
| Updated: | Jun 10 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Greg McManus of iDEFENSE Labs. |
| Vulnerable: |
RealNetworks RealPlayer 10 Japanese RealNetworks RealPlayer 10 German RealNetworks RealPlayer 10 English |
| Not Vulnerable: | |
Discussion
RealNetworks RealPlayer URI Processing Buffer Overrun Vulnerability
A remote buffer overflow vulnerability is reported to affect RealPlayer 10; previous versions may also be prone to this issue. It is reported that the vulnerability presents itself when RealPlayer processes a URI that contains a large number of period characters. A remote attacker may potentially exploit this vulnerability in order to execute arbitrary supplied code in the context of the user who is running the affected software.
RealNetworks has released updates to the products affected by these issues, and users are urged to upgrade immediately.
A remote buffer overflow vulnerability is reported to affect RealPlayer 10; previous versions may also be prone to this issue. It is reported that the vulnerability presents itself when RealPlayer processes a URI that contains a large number of period characters. A remote attacker may potentially exploit this vulnerability in order to execute arbitrary supplied code in the context of the user who is running the affected software.
RealNetworks has released updates to the products affected by these issues, and users are urged to upgrade immediately.
Exploit / POC
RealNetworks RealPlayer URI Processing Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RealNetworks RealPlayer URI Processing Buffer Overrun Vulnerability
Solution:
RealNetworks has released updates to the affected software. Please see the referenced web page from RealNetworks for further information on obtaining the fixes.
It is suggested that users use the "Check for Updates" options in the software to automatically upgrade the software.
Solution:
RealNetworks has released updates to the affected software. Please see the referenced web page from RealNetworks for further information on obtaining the fixes.
It is suggested that users use the "Check for Updates" options in the software to automatically upgrade the software.
References
RealNetworks RealPlayer URI Processing Buffer Overrun Vulnerability
References:
References:
- Real Networks RealPlayer URL Parsing Buffer Overflow Vulnerability (iDEFENSE)
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities. (RealNetworks)
- RealPlayer Homepage (Real Networks)