RealNetwork RealPlayer EMBD3260.DLL Error Response Heap Overflow Vulnerability
BID:10528
Info
RealNetwork RealPlayer EMBD3260.DLL Error Response Heap Overflow Vulnerability
| Bugtraq ID: | 10528 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2004 12:00AM |
| Updated: | Jun 10 2004 12:00AM |
| Credit: | This vulnerability was discovered by Karl Lynn, with additional research by Derek Soeder. |
| Vulnerable: |
RealNetworks RealPlayer Enterprise RealNetworks RealPlayer 8 RealNetworks RealPlayer 10 Japanese RealNetworks RealPlayer 10 German RealNetworks RealPlayer 10 English RealNetworks RealPlayer 10.0 BETA RealNetworks RealPlayer 10.0 v6.0.12.690 RealNetworks RealPlayer 8.0 Win32 RealNetworks RealPlayer 8.0 Unix RealNetworks RealPlayer 8.0 Mac RealNetworks RealOne Player 6.0.11 .872 RealNetworks RealOne Player 6.0.11 .868 RealNetworks RealOne Player 6.0.11 .853 RealNetworks RealOne Player 6.0.11 .841 RealNetworks RealOne Player 6.0.11 .830 RealNetworks RealOne Player 6.0.11 .818 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 RealNetworks RealOne Player RealNetworks RealOne Enterprise Desktop 6.0.11 .774 |
| Not Vulnerable: | |
Discussion
RealNetwork RealPlayer EMBD3260.DLL Error Response Heap Overflow Vulnerability
eEye has reported that heap overflow vulnerabilities exist in RealNetworks RealPlayer releases. These issues may be triggered by a malformed movie file embedded in an HTML page. If successfully exploited, it is possible to execute arbitrary code in the context of the user running the player.
eEye has reported that heap overflow vulnerabilities exist in RealNetworks RealPlayer releases. These issues may be triggered by a malformed movie file embedded in an HTML page. If successfully exploited, it is possible to execute arbitrary code in the context of the user running the player.
Exploit / POC
RealNetwork RealPlayer EMBD3260.DLL Error Response Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RealNetwork RealPlayer EMBD3260.DLL Error Response Heap Overflow Vulnerability
Solution:
RealNetworks has released updates to the affected software. Please see the referenced web page from RealNetworks for further information on obtaining the fixes.
It is suggested that users use the "Check for Updates" options in the software to automatically upgrade the software.
Solution:
RealNetworks has released updates to the affected software. Please see the referenced web page from RealNetworks for further information on obtaining the fixes.
It is suggested that users use the "Check for Updates" options in the software to automatically upgrade the software.
References
RealNetwork RealPlayer EMBD3260.DLL Error Response Heap Overflow Vulnerability
References:
References:
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities. (RealNetworks)
- EEYE: RealPlayer embd3260.dll Error Response Heap Overflow ("Derek Soeder"
)