RealPlayer RealFlash Source Loading Buffer Overflow Vulnerability
BID:6230
Info
RealPlayer RealFlash Source Loading Buffer Overflow Vulnerability
| Bugtraq ID: | 6230 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2002 12:00AM |
| Updated: | Nov 22 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to NGSSoftware. |
| Vulnerable: |
RealNetworks RealPlayer 8.0 Win32 RealNetworks RealPlayer 7.0 Win32 RealNetworks RealPlayer 6.0 Win32 RealNetworks RealPlayer G2 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player |
| Not Vulnerable: | |
Discussion
RealPlayer RealFlash Source Loading Buffer Overflow Vulnerability
A buffer overflow has been discovered in RealOne Player when viewing malicious RealFlash presentations. When a vulnerable player attempts to play the presentation, a buffer will be overrun, resulting in memory corruption.
Successful exploitation of this issue may allow an attacker to execute arbitrary code with the privleges of the user running RealOne player.
Precise technical details regarding this vulnerability are not yet known. This BID will be updated as further information becomes available.
** Reports indicate that the patch for this issue supplied by Real Networks does not correct the problem.
A buffer overflow has been discovered in RealOne Player when viewing malicious RealFlash presentations. When a vulnerable player attempts to play the presentation, a buffer will be overrun, resulting in memory corruption.
Successful exploitation of this issue may allow an attacker to execute arbitrary code with the privleges of the user running RealOne player.
Precise technical details regarding this vulnerability are not yet known. This BID will be updated as further information becomes available.
** Reports indicate that the patch for this issue supplied by Real Networks does not correct the problem.
Exploit / POC
RealPlayer RealFlash Source Loading Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RealPlayer RealFlash Source Loading Buffer Overflow Vulnerability
Solution:
Real Networks have released an upgrade which addresses the issue.
** Note that reports indicate that the patch supplied by Real Networks for this issue does not rectify the problem.
RealNetworks RealOne Player
RealNetworks RealOne Player 2.0
Solution:
Real Networks have released an upgrade which addresses the issue.
** Note that reports indicate that the patch supplied by Real Networks for this issue does not rectify the problem.
RealNetworks RealOne Player
-
Real Networks skinpatchr11s.rmp
http://service.real.com/help/faq/security/07092002/skinpatchr11s.rmp
RealNetworks RealOne Player 2.0
-
Real Networks skinpatchr11s.rmp
http://service.real.com/help/faq/security/07092002/skinpatchr11s.rmp
References
RealPlayer RealFlash Source Loading Buffer Overflow Vulnerability
References:
References:
- RealPlayer Buffer Overrun Vulnerability (Real Networks)
- RealPlayer security fix is faulty (The Register)