RealOne Player SMIL File Heap Corruption Vulnerability
BID:6227
Info
RealOne Player SMIL File Heap Corruption Vulnerability
| Bugtraq ID: | 6227 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Nov 22 2002 12:00AM |
| Updated: | Nov 22 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to NGSSoftware. |
| Vulnerable: |
RealNetworks RealPlayer 8.0 Win32 RealNetworks RealPlayer 7.0 Win32 RealNetworks RealPlayer 6.0 Win32 RealNetworks RealPlayer G2 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player |
| Not Vulnerable: | |
Discussion
RealOne Player SMIL File Heap Corruption Vulnerability
A buffer overrun has been discovered in RealPlayer/RealOne Player.
By constructing a malicious Synchronized Multimedia Integration Language (SMIL) file, it may be possible to trigger the overrun. Successful exploitation of this issue will result in heap corruption, which may allow for the execution of attacker-supplied code.
** Reports indicate that the patch for this issue supplied by Real Networks does not correct the problem.
A buffer overrun has been discovered in RealPlayer/RealOne Player.
By constructing a malicious Synchronized Multimedia Integration Language (SMIL) file, it may be possible to trigger the overrun. Successful exploitation of this issue will result in heap corruption, which may allow for the execution of attacker-supplied code.
** Reports indicate that the patch for this issue supplied by Real Networks does not correct the problem.
Exploit / POC
RealOne Player SMIL File Heap Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RealOne Player SMIL File Heap Corruption Vulnerability
Solution:
Real Networks has released a patch which addresses this issue.
** Note that reports indicate that the patch supplied by Real Networks for this issue does not rectify the problem.
RealNetworks RealOne Player
RealNetworks RealOne Player 2.0
Solution:
Real Networks has released a patch which addresses this issue.
** Note that reports indicate that the patch supplied by Real Networks for this issue does not rectify the problem.
RealNetworks RealOne Player
-
Real Networks skinpatchr11s.rmp
http://service.real.com/help/faq/security/07092002/skinpatchr11s.rmp
RealNetworks RealOne Player 2.0
-
Real Networks skinpatchr11s.rmp
http://service.real.com/help/faq/security/07092002/skinpatchr11s.rmp
References
RealOne Player SMIL File Heap Corruption Vulnerability
References:
References:
- RealPlayer Buffer Overrun Vulnerability (Real Networks)
- RealPlayer security fix is faulty (The Register)