Real Media RealPlayer Media File Buffer Overflow Vulnerability
BID:3809
Info
Real Media RealPlayer Media File Buffer Overflow Vulnerability
| Bugtraq ID: | 3809 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2002 12:00AM |
| Updated: | Jan 05 2002 12:00AM |
| Credit: | This vulnerability was announced by <[email protected]> via the Vuln-Dev mailing list on January 5, 2002. |
| Vulnerable: |
RealNetworks RealPlayer Intranet 8.0 RealNetworks RealPlayer Intranet 7.0 RealNetworks RealPlayer 8.0 Win32 RealNetworks RealPlayer 8.0 Unix RealNetworks RealPlayer 8.0 Mac RealNetworks RealPlayer 7.0 Win32 RealNetworks RealPlayer 7.0 Unix RealNetworks RealPlayer 7.0 Mac RealNetworks RealPlayer G2 RealNetworks RealOne Player for Linux 2.2 Alpha RealNetworks RealOne Player |
| Not Vulnerable: | |
Discussion
Real Media RealPlayer Media File Buffer Overflow Vulnerability
RealPlayer is a software package distributed and maintained by Real Media. It is available for Microsoft Windows, Unix, and Linux.
A problem with the handling of file format may make it possible to remotely crash RealPlayer. The problem could also potentially result in code execution.
Upon receiving a file with a malformed header, it is possible to crash the RealPlayer client. A file that specifies a content length greater than the actual size creates a circumstance where RealPlayer reacts unpredictably and becomes unstable. This usually results in the crashing of RealPlayer. This problem may also make it possible to execute arbitrary code.
RealPlayer is a software package distributed and maintained by Real Media. It is available for Microsoft Windows, Unix, and Linux.
A problem with the handling of file format may make it possible to remotely crash RealPlayer. The problem could also potentially result in code execution.
Upon receiving a file with a malformed header, it is possible to crash the RealPlayer client. A file that specifies a content length greater than the actual size creates a circumstance where RealPlayer reacts unpredictably and becomes unstable. This usually results in the crashing of RealPlayer. This problem may also make it possible to execute arbitrary code.
Exploit / POC
Real Media RealPlayer Media File Buffer Overflow Vulnerability
An exploit has been provided by UNYUN ([email protected]). See included message for further details.
An exploit has been provided by UNYUN ([email protected]). See included message for further details.
Solution / Fix
Real Media RealPlayer Media File Buffer Overflow Vulnerability
Solution:
Fixes for most versions can be obtained using the RealPlayer AutoUpdate Service.
Fixes will not be made available for RealPlayer 7 and RealPlayer G2 users. Those affected are advised to upgrade to RealOne Player or RealPlayer 8.
Users of RealPlayer Intranet versions 8 or 7 should install the rmff3260.dll library.
Users of RealPlayer for UNIX version 8 or RealOne Player Alpha for Linux are advised to download the rmffplin.so.6.0 library and copy the file "rmffplin.so.6.0" to the ~/RealPlayer8/Plugins directory (or wherever the Plugins directory happens to be located).
RealNetworks RealOne Player for Linux 2.2 Alpha
RealNetworks RealPlayer Intranet 7.0
RealNetworks RealPlayer 8.0 Unix
RealNetworks RealPlayer Intranet 8.0
Solution:
Fixes for most versions can be obtained using the RealPlayer AutoUpdate Service.
Fixes will not be made available for RealPlayer 7 and RealPlayer G2 users. Those affected are advised to upgrade to RealOne Player or RealPlayer 8.
Users of RealPlayer Intranet versions 8 or 7 should install the rmff3260.dll library.
Users of RealPlayer for UNIX version 8 or RealOne Player Alpha for Linux are advised to download the rmffplin.so.6.0 library and copy the file "rmffplin.so.6.0" to the ~/RealPlayer8/Plugins directory (or wherever the Plugins directory happens to be located).
RealNetworks RealOne Player for Linux 2.2 Alpha
-
Real Networks rmffplin.so.6.0.6.0-linux-2.2-libc6-i386.gz
http://docs.real.com/docs/playerpatch/RealOne_alpha/rmffplin.so.6.0.6. 0-linux-2.2-libc6-i386.gz
RealNetworks RealPlayer Intranet 7.0
-
Real Networks rmff3260.dll
http://docs.real.com/docs/playerpatch/rmff3260.dll
RealNetworks RealPlayer 8.0 Unix
-
Real Networks rmffplin.so.6.0-linux-2.0-libc6-i386.gz
http://docs.real.com/docs/playerpatch/RP8_gold/rmffplin.so.6.0-linux-2 .0-libc6-i386.gz -
Real Networks rmffplin.so.6.0-linux-2.2-libc6-i386.gz
http://docs.real.com/docs/playerpatch/RP8_gold/rmffplin.so.6.0-linux-2 .2-libc6-i386.gz
RealNetworks RealPlayer Intranet 8.0
-
Real Networks rmff3260.dll
http://docs.real.com/docs/playerpatch/rmff3260.dll
References
Real Media RealPlayer Media File Buffer Overflow Vulnerability
References:
References:
- RealPlayer Frequently Asked Questions (Real Networks)
- RealPlayer Homepage (Real Networks)
- Sentinel Chicken Networks Security Advisory #01 (Sentinel Chicken)