Real Networks RealPlayer & RealPlayer SP Multiple Security Vulnerabilities
BID:42775
Info
Real Networks RealPlayer & RealPlayer SP Multiple Security Vulnerabilities
| Bugtraq ID: | 42775 |
| Class: | Unknown |
| CVE: |
CVE-2010-0116 CVE-2010-0117 CVE-2010-0120 CVE-2010-2996 CVE-2010-3000 CVE-2010-3001 CVE-2010-3002 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2010 12:00AM |
| Updated: | May 17 2011 08:12PM |
| Credit: | An anonymous researchers working with TippingPoint's Zero Day Initiative; Behrang Fouladi of SensePost; Alin Rad Pop of Secunia Research; Carsten Eiram of Secunia Research; Steve Manzuik of Microsoft Vulnerability Research (MSVR); Sebastian Apelt, siberas, |
| Vulnerable: |
Real Networks RealPlayer SP 1.1.4 Real Networks RealPlayer SP 1.0.5 Real Networks RealPlayer SP 1.0.2 Real Networks RealPlayer SP 1.0.1 Real Networks RealPlayer SP 1.0 Real Networks RealPlayer 11 Beta 6.0.14 .550 Real Networks RealPlayer 11.0.5 Real Networks RealPlayer 11.0.4 Real Networks RealPlayer 11.0.3 Real Networks RealPlayer 11.0.2 Real Networks RealPlayer 11.0.1 Real Networks RealPlayer 11.1 Real Networks RealPlayer 11 Beta Real Networks RealPlayer 11 |
| Not Vulnerable: |
Real Networks RealPlayer SP 1.1.5 |
Discussion
Real Networks RealPlayer & RealPlayer SP Multiple Security Vulnerabilities
Real Networks RealPlayer & RealPlayer SP are prone to multiple security vulnerabilities, including remote code-execution issues, an unauthorized access issue, a potential denial-of-service issue, and an unspecified issue.
Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected application, cause denial-of-service conditions, or access files without proper authorization. Other attacks may also be possible.
RealPlayer 11.1 and RealPlayer SP 1.1.4 and prior are vulnerable.
Real Networks RealPlayer & RealPlayer SP are prone to multiple security vulnerabilities, including remote code-execution issues, an unauthorized access issue, a potential denial-of-service issue, and an unspecified issue.
Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected application, cause denial-of-service conditions, or access files without proper authorization. Other attacks may also be possible.
RealPlayer 11.1 and RealPlayer SP 1.1.4 and prior are vulnerable.
Exploit / POC
Real Networks RealPlayer & RealPlayer SP Multiple Security Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof of concept is available for CVE-2010-3000:
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof of concept is available for CVE-2010-3000:
Solution / Fix
Real Networks RealPlayer & RealPlayer SP Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Real Networks RealPlayer & RealPlayer SP Multiple Security Vulnerabilities
References:
References:
- RealPlayer Homepage (Real Networks )
- Secunia Research: RealPlayer QCP Audio Content Parsing Buffer Overflow (Secunia)
- Secunia Research: RealPlayer QCP Parsing Integer Overflow Vulnerability (Secunia)
- Secunia Research: RealPlayer YUV420 Transformation Processing Vulnerability (Secunia)
- ZDI-10-166: RealNetworks RealPlayer Malformed IVR Object Index Code Execution Vu (ZDI Disclosures
) - ZDI-10-167: RealNetworks RealPlayer FLV Parsing Multiple Integer Overflow Vulner (ZDI Disclosures
) - Microsoft Vulnerability Research Advisory MSVR11-003 (Microsoft)
- RealNetworks, Inc. Releases Update to Address Security Vulnerabilities (Real Networks)
- ZDI-10-166 RealNetworks RealPlayer Malformed IVR Object Index Code Execution Vul (Zero Day Initiative)
- ZDI-10-167: RealNetworks RealPlayer FLV Parsing Multiple Integer Overflow Vulner (Zero Day Initiative)