RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability
BID:7177
Info
RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability
| Bugtraq ID: | 7177 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0141 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 28 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery is credited to Juliano Rizzo, Agustin Azubel Friedman, Bruno Acselrad and Carlos Sarraute from Core Security Technologies. |
| Vulnerable: |
RealNetworks RealPlayer 8.0 Win32 RealNetworks RealPlayer 8.0 Unix RealNetworks RealPlayer 8.0 Mac RealNetworks RealOne Player Gold for Windows 6.0.10 .505 RealNetworks RealOne Player for OSX 9.0 .297 RealNetworks RealOne Player for OSX 9.0 .288 RealNetworks RealOne Player 6.0.11 .853 RealNetworks RealOne Player 6.0.11 .841 RealNetworks RealOne Player 6.0.11 .830 RealNetworks RealOne Player 6.0.11 .818 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player RealNetworks RealOne Enterprise Desktop 6.0.11 .774 |
| Not Vulnerable: | |
Discussion
RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability
A heap corruption vulnerability has been reported for RealPlayer that may result in the execution of attacker-supplied code.
The vulnerability is related to the way RealPlayer handles PNG image files. Specifically, the vulnerability occurs when RealPlayer attempts to decompress PNG image files.
An attacker can exploit this vulnerability by tricking a user into viewing a maliciously constructed PNG image file. When the image file is rendered by the RealPlayer, it will trigger the heap corruption condition and overwrite critical areas in memory with attacker-supplied values.
A heap corruption vulnerability has been reported for RealPlayer that may result in the execution of attacker-supplied code.
The vulnerability is related to the way RealPlayer handles PNG image files. Specifically, the vulnerability occurs when RealPlayer attempts to decompress PNG image files.
An attacker can exploit this vulnerability by tricking a user into viewing a maliciously constructed PNG image file. When the image file is rendered by the RealPlayer, it will trigger the heap corruption condition and overwrite critical areas in memory with attacker-supplied values.
Solution / Fix
RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability
Solution:
RealNetworks has released fixes for this issue.
For RealOne Player and RealOne Player version 2, follow these steps:
1. Select Tools from the menu.
2. Click "Check for Update".
3. Check the box next to "Security Update - March 2003".
4. Click the Install button.
For RealPlayer 8, follow these steps:
1. Select Help from the menu.
2. Click "Check for Update".
3. Check the box next to "Security Update - March 2003".
4. Click the Install button.
RealOne Player for OS X users are advised to download an updated RealOne Player from http://forms.real.com/real/realone/mac.html.
A fix for RealOne Desktop Manager and RealOne Enterprise Desktop is forthcoming.
Users of other versions of RealPlayer and RealOne Player are advised to upgrade to the newest version of RealOne Player, then follow the steps above.
RealPlayer 8 for MacOS users should download the fix below, then follow these steps:
1. Decompress the RP8_Security_March03.sit.hqx archive using Stuffit Expander.
2. Close RealPlayer if it is running.
3. Copy the following update files from the archive to the System Folder:Application Support:Real:Plugins folder:
pxpf60.dll
pxpr60.dll
pxgr60.dll
pxcpng60.dll
httpfsys60.dll
swfrend60.dll
RealNetworks RealPlayer 8.0 Mac
Solution:
RealNetworks has released fixes for this issue.
For RealOne Player and RealOne Player version 2, follow these steps:
1. Select Tools from the menu.
2. Click "Check for Update".
3. Check the box next to "Security Update - March 2003".
4. Click the Install button.
For RealPlayer 8, follow these steps:
1. Select Help from the menu.
2. Click "Check for Update".
3. Check the box next to "Security Update - March 2003".
4. Click the Install button.
RealOne Player for OS X users are advised to download an updated RealOne Player from http://forms.real.com/real/realone/mac.html.
A fix for RealOne Desktop Manager and RealOne Enterprise Desktop is forthcoming.
Users of other versions of RealPlayer and RealOne Player are advised to upgrade to the newest version of RealOne Player, then follow the steps above.
RealPlayer 8 for MacOS users should download the fix below, then follow these steps:
1. Decompress the RP8_Security_March03.sit.hqx archive using Stuffit Expander.
2. Close RealPlayer if it is running.
3. Copy the following update files from the archive to the System Folder:Application Support:Real:Plugins folder:
pxpf60.dll
pxpr60.dll
pxgr60.dll
pxcpng60.dll
httpfsys60.dll
swfrend60.dll
RealNetworks RealPlayer 8.0 Mac
-
RealNetworks RP8_Security_March03.sit.hqx
http://service.real.com/help/faq/security/03272003/RP8_Security_March0 3.sit.hqx
References
RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability
References:
References: