RealNetworks RealPlayer IVR File Parsing Multiple Buffer Overflow Vulnerabilities
BID:33652
Info
RealNetworks RealPlayer IVR File Parsing Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 33652 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0375 CVE-2009-0376 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2009 12:00AM |
| Updated: | Jan 21 2010 07:01PM |
| Credit: | Haifei Li of Fortinet's FortiGuard Global Security Research Team |
| Vulnerable: |
RealNetworks RealPlayer 11.0.5 RealNetworks RealPlayer 11.0.4 RealNetworks RealPlayer 11.0.3 RealNetworks RealPlayer 11.0.2 RealNetworks RealPlayer 11.0.1 RealNetworks RealPlayer 11 |
| Not Vulnerable: | |
Discussion
RealNetworks RealPlayer IVR File Parsing Multiple Buffer Overflow Vulnerabilities
RealNetworks RealPlayer is prone to multiple memory-corruption vulnerabilities:
- An unspecified memory-corruption vulnerability when parsing IVR files.
- A memory-corruption vulnerability when parsing size values in an IVR file.
Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will cause a denial-of-service condition.
RealPlayer 11 is affected; other versions may also be vulnerable.
RealNetworks RealPlayer is prone to multiple memory-corruption vulnerabilities:
- An unspecified memory-corruption vulnerability when parsing IVR files.
- A memory-corruption vulnerability when parsing size values in an IVR file.
Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will cause a denial-of-service condition.
RealPlayer 11 is affected; other versions may also be vulnerable.
Exploit / POC
RealNetworks RealPlayer IVR File Parsing Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
RealNetworks RealPlayer IVR File Parsing Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
RealNetworks RealPlayer IVR File Parsing Multiple Buffer Overflow Vulnerabilities
References:
References:
- Fortinet discovers multiple vulnerabilities in RealNetworks' RealPlayer (Fortinet's FortiGuard Global Security Research Team)
- RealPlayer Homepage (Real Networks )
- RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilitie (Fortinet's FortiGuard Global Security Research Team)
- RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilitie ("[email protected]"
) - RealNetworks, Inc. Releases Update to Address Security Vulnerabilities. (RealNetworks)