RealNetworks Real and RealOne Player Unspecified MP3 ActiveX Control Execution Vulnerability
BID:14073
Info
RealNetworks Real and RealOne Player Unspecified MP3 ActiveX Control Execution Vulnerability
| Bugtraq ID: | 14073 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2005 12:00AM |
| Updated: | Jun 27 2005 12:00AM |
| Credit: | Discovery of this issue is credited to "NGSSoftware Insight Security Research" <[email protected]>. |
| Vulnerable: |
RealNetworks RealPlayer 10.5 v6.0.12.1069 RealNetworks RealPlayer 10.5 v6.0.12.1059 RealNetworks RealPlayer 10.5 v6.0.12.1056 RealNetworks RealPlayer 10.5 v6.0.12.1053 RealNetworks RealPlayer 10.5 v6.0.12.1040 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 |
| Not Vulnerable: | |
Discussion
RealNetworks Real and RealOne Player Unspecified MP3 ActiveX Control Execution Vulnerability
NGSSoftware report that a vulnerability affects RealPlayer for Windows. Reports indicate that the issue may be exploited to overwrite an arbitrary file or execute an ActiveX control using a specially formatted malicious MP3 file.
Details about this vulnerability have been withheld until a later date (Sep 27th, 2005). This BID will be updated as soon as this information is made available.
NGSSoftware report that a vulnerability affects RealPlayer for Windows. Reports indicate that the issue may be exploited to overwrite an arbitrary file or execute an ActiveX control using a specially formatted malicious MP3 file.
Details about this vulnerability have been withheld until a later date (Sep 27th, 2005). This BID will be updated as soon as this information is made available.
Exploit / POC
RealNetworks Real and RealOne Player Unspecified MP3 ActiveX Control Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RealNetworks Real and RealOne Player Unspecified MP3 ActiveX Control Execution Vulnerability
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the referenced advisory for further information.
References
RealNetworks Real and RealOne Player Unspecified MP3 ActiveX Control Execution Vulnerability
References:
References:
- Home Page (Real Networks)
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities (RealNetworks)
- High Risk Vulnerability in RealPlayer for Windows ("NGSSoftware Insight Security Research"
)