RealNetworks RealPlayer 'rmoc3260.dll' ActiveX Control Memory Corruption Vulnerability
BID:28157
Info
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX Control Memory Corruption Vulnerability
| Bugtraq ID: | 28157 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1309 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Jul 28 2008 05:47PM |
| Credit: | Elazar Broad and Peter Vreugdenhil. |
| Vulnerable: |
RealNetworks rmoc3260.dll 6.0.10 .45 RealNetworks RealPlayer Enterprise RealNetworks RealPlayer 11.0.2 RealNetworks RealPlayer 10.5 v6.0.12.1483 RealNetworks RealPlayer 10.5 v6.0.12.1483 RealNetworks RealPlayer 10.5 v6.0.12.1348 RealNetworks RealPlayer 10.5 v6.0.12.1235 RealNetworks RealPlayer 10.5 v6.0.12.1069 RealNetworks RealPlayer 10.5 v6.0.12.1059 RealNetworks RealPlayer 10.5 v6.0.12.1056 RealNetworks RealPlayer 10.5 v6.0.12.1053 RealNetworks RealPlayer 10.5 v6.0.12.1040 RealNetworks RealPlayer 10.5 Beta v6.0.12.1016 RealNetworks RealPlayer 10.5 RealNetworks RealPlayer 10.0 RealNetworks RealPlayer 11 |
| Not Vulnerable: |
RealNetworks rmoc3260.dll 6.0.10 .50 RealNetworks RealPlayer 11.0.3 RealNetworks RealPlayer 10.5 v6.0.12.1675 |
Discussion
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX Control Memory Corruption Vulnerability
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX control is prone to a memory-corruption vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely crash the application.
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX control is prone to a memory-corruption vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely crash the application.
Exploit / POC
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX Control Memory Corruption Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
UPDATE (April 3, 2008): This issue is being actively exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit code are available:
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
UPDATE (April 3, 2008): This issue is being actively exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit code are available:
Solution / Fix
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX Control Memory Corruption Vulnerability
Solution:
The vendor addressed this issue in RealPlayer 11.0.3. Please contact the vendor for details.
Solution:
The vendor addressed this issue in RealPlayer 11.0.3. Please contact the vendor for details.
References
RealNetworks RealPlayer 'rmoc3260.dll' ActiveX Control Memory Corruption Vulnerability
References:
References:
- July 25, 2008 - RealNetworks, Inc. Releases Update to Address Security Vulnerabi (Real Networks)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- RealPlayer Homepage (Real Networks)
- ZDI-08-047: RealNetworks RealPlayer rmoc3260 ActiveX Control Memory Corruption V (ZDI)
- Vulnerability Note VU#831457 RealNetworks RealPlayer ActiveX controls property h (US-CERT)