RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability
BID:15382
Info
RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability
| Bugtraq ID: | 15382 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2630 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Discovery is credited to Fang Xing of eEye Digital Security. |
| Vulnerable: |
RealNetworks RealPlayer 10.5 v6.0.12.1235 RealNetworks RealPlayer 10.5 v6.0.12.1069 RealNetworks RealPlayer 10.5 v6.0.12.1059 RealNetworks RealPlayer 10.5 v6.0.12.1056 RealNetworks RealPlayer 10.5 v6.0.12.1053 RealNetworks RealPlayer 10.5 v6.0.12.1040 RealNetworks RealPlayer 10.0 RealNetworks RealPlayer 8.0 Win32 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 |
| Not Vulnerable: | |
Discussion
RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability
A heap overflow vulnerability exists in RealPlayer on Windows platforms.
The issue arises when 'DUNZIP32.DLL' is called to handle a malformed file.
A successful attack can allow the attacker to gain unauthorized access to a vulnerable computer.
A heap overflow vulnerability exists in RealPlayer on Windows platforms.
The issue arises when 'DUNZIP32.DLL' is called to handle a malformed file.
A successful attack can allow the attacker to gain unauthorized access to a vulnerable computer.
Exploit / POC
RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability
Solution:
The vendor has released fixes to address this issue. The patches are available through the 'Check for Update' functionality of the software under the 'Tools' menu. Fixes are available from the following location as well:
http://service.real.com/realplayer/security/
Solution:
The vendor has released fixes to address this issue. The patches are available through the 'Check for Update' functionality of the software under the 'Tools' menu. Fixes are available from the following location as well:
http://service.real.com/realplayer/security/
References
RealNetworks RealPlayer DUNZIP32.DLL Heap Overflow Vulnerability
References:
References:
- Home Page (Real Networks)
- [EEYEB-20050701] - RealPlayer Zipped Skin File Buffer Overflow II (
)