RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability
BID:14048
Info
RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability
| Bugtraq ID: | 14048 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1277 CVE-2005-1766 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2005 12:00AM |
| Updated: | Mar 06 2007 11:55PM |
| Credit: | An anonymous discoverer reported this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 RealNetworks RealPlayer Intranet 8.0 RealNetworks RealPlayer Intranet 7.0 RealNetworks RealPlayer for Windows 7.0 RealNetworks RealPlayer For Unix 10.0.4 RealNetworks RealPlayer For Unix 10.0.3 RealNetworks RealPlayer Enterprise 1.7 RealNetworks RealPlayer Enterprise 1.6 RealNetworks RealPlayer Enterprise 1.5 RealNetworks RealPlayer Enterprise 1.2 RealNetworks RealPlayer Enterprise 1.1 RealNetworks RealPlayer Enterprise RealNetworks RealPlayer 8 RealNetworks RealPlayer 10 for Mac OS 10.0 .0.331 RealNetworks RealPlayer 10 for Mac OS Beta RealNetworks RealPlayer 10 for Mac OS 10.0.0.325 RealNetworks RealPlayer 10 for Mac OS 10.0.0.305 RealNetworks RealPlayer 10 for Mac OS RealNetworks RealPlayer 10 for Linux RealNetworks RealPlayer 10 Japanese RealNetworks RealPlayer 10 German RealNetworks RealPlayer 10 English RealNetworks RealPlayer 10.5 v6.0.12.1069 RealNetworks RealPlayer 10.5 v6.0.12.1059 RealNetworks RealPlayer 10.5 v6.0.12.1056 RealNetworks RealPlayer 10.5 v6.0.12.1053 RealNetworks RealPlayer 10.5 v6.0.12.1040 RealNetworks RealPlayer 10.5 Beta v6.0.12.1016 RealNetworks RealPlayer 10.5 RealNetworks RealPlayer 10.0 BETA RealNetworks RealPlayer 10.0 v6.0.12.690 RealNetworks RealPlayer 10.0 RealNetworks RealPlayer 8.0 Win32 RealNetworks RealPlayer 8.0 Unix RealNetworks RealPlayer 8.0 Mac RealNetworks RealPlayer 7.0 Win32 RealNetworks RealPlayer 7.0 Unix RealNetworks RealPlayer 7.0 Mac RealNetworks RealPlayer 6.0 Win32 RealNetworks RealPlayer 6.0 Unix RealNetworks RealPlayer G2 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 RealNetworks Helix Player for Linux 1.0.4 Gentoo Linux |
| Not Vulnerable: | |
Discussion
RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability
RealPlayer is prone to a remote heap-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Specifically, the application fails to bounds-check user-supplied data contained in RealText files, resulting in the possibility of overflowing a heap buffer. Attackers can control the contents of critical memory control structures and write arbitrary data to arbitrary memory locations.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of the user running the affected application.
RealPlayer is prone to a remote heap-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Specifically, the application fails to bounds-check user-supplied data contained in RealText files, resulting in the possibility of overflowing a heap buffer. Attackers can control the contents of critical memory control structures and write arbitrary data to arbitrary memory locations.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of the user running the affected application.
Exploit / POC
RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this and other issues. Please see the referenced advisories for information on obtaining fixes.
RealNetworks Helix Player for Linux 1.0.4
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Personal 9.3
Solution:
The vendor has released an advisory along with fixes to address this and other issues. Please see the referenced advisories for information on obtaining fixes.
RealNetworks Helix Player for Linux 1.0.4
-
Debian helix-player_1.0.4-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/helix-player/helix-play er_1.0.4-1sarge1_i386.deb -
Debian helix-player_1.0.4-1sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/h/helix-player/helix-play er_1.0.4-1sarge1_powerpc.deb
S.u.S.E. Linux Personal 9.2
-
S.u.S.E. RealPlayer-10.0.5-0.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/RealPlayer-10.0.5 -0.1.i586.rpm
S.u.S.E. Linux Professional 9.2
-
S.u.S.E. RealPlayer-10.0.5-0.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/RealPlayer-10.0.5 -0.1.i586.rpm
S.u.S.E. Linux Professional 9.3
-
S.u.S.E. RealPlayer-10.0.5-0.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/RealPlayer-10.0.5 -0.1.i586.rpm
S.u.S.E. Linux Personal 9.3
-
S.u.S.E. RealPlayer-10.0.5-0.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/RealPlayer-10.0.5 -0.1.i586.rpm
References
RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability
References:
References:
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities (RealNetworks)
- RealPlayer Homepage (Real Networks)
- RHSA-2005:517-02 - HelixPlayer security update (RedHat)
- RHSA-2005:523-05 - RealPlayer security update (RedHat)
- RHSA-2005:523-09 - RealPlayer security update (RedHat)
- Upcoming Advisories: EEYEB-20050504 (eEye Digital Security)
- eEye Advisory - EEYEB-200505 - RealPlayer AVI Processing Overflow (
) - iDEFENSE Security Advisory 06.23.05: RealNetworks RealPlayer RealText Parsing He ("iDEFENSE Labs"
)