RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability

BID:7177

Info

RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability

Bugtraq ID: 7177
Class: Boundary Condition Error
CVE: CVE-2003-0141
Remote: Yes
Local: Yes
Published: Mar 28 2003 12:00AM
Updated: Jul 11 2009 09:06PM
Credit: Discovery is credited to Juliano Rizzo, Agustin Azubel Friedman, Bruno Acselrad and Carlos Sarraute from Core Security Technologies.
Vulnerable: RealNetworks RealPlayer 8.0 Win32
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98 SP1
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
RealNetworks RealPlayer 8.0 Unix
- Caldera OpenLinux Workstation 3.1
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 alpha
- HP HP-UX 11.11
- HP HP-UX 11.0
- IBM AIX 4.3.3
- IBM AIX 4.3.2
- IBM AIX 4.3.1
- IBM AIX 4.3
- IBM AIX 4.2.1
- IBM AIX 4.2
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- Redhat Linux 7.2 i386
- Redhat Linux 7.1 i386
- Redhat Linux 7.0 i386
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
+ S.u.S.E. Linux Personal 9.1
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
+ S.u.S.E. Linux Personal 8.2
- SCO eDesktop 2.4
- SGI IRIX 6.5.14
- SGI IRIX 6.5.13 m
- SGI IRIX 6.5.13 f
- SGI IRIX 6.5.13
- SGI IRIX 6.5.12 m
- SGI IRIX 6.5.12 f
- SGI IRIX 6.5.12
- SGI IRIX 6.5.11 m
- SGI IRIX 6.5.11 f
- SGI IRIX 6.5.11
- SGI IRIX 6.3
- Slackware Linux 8.0
- Slackware Linux 7.1
- Slackware Linux 7.0
- Sun Solaris 7.0
- Sun Solaris 2.6
+ SuSE Linux 8.1
- SuSE Linux 7.2 i386
- SuSE Linux 7.1 x86
- SuSE Linux 7.1
- SuSE Linux 7.0 i386
+ SuSE Linux Desktop 1.0
RealNetworks RealPlayer 8.0 Mac
RealNetworks RealOne Player Gold for Windows 6.0.10 .505
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 95 SR2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
RealNetworks RealOne Player for OSX 9.0 .297
RealNetworks RealOne Player for OSX 9.0 .288
RealNetworks RealOne Player 6.0.11 .853
RealNetworks RealOne Player 6.0.11 .841
RealNetworks RealOne Player 6.0.11 .830
RealNetworks RealOne Player 6.0.11 .818
RealNetworks RealOne Player 2.0
RealNetworks RealOne Player
RealNetworks RealOne Enterprise Desktop 6.0.11 .774
Not Vulnerable:

Discussion

RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability

A heap corruption vulnerability has been reported for RealPlayer that may result in the execution of attacker-supplied code.

The vulnerability is related to the way RealPlayer handles PNG image files. Specifically, the vulnerability occurs when RealPlayer attempts to decompress PNG image files.

An attacker can exploit this vulnerability by tricking a user into viewing a maliciously constructed PNG image file. When the image file is rendered by the RealPlayer, it will trigger the heap corruption condition and overwrite critical areas in memory with attacker-supplied values.

Solution / Fix

RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability

Solution:
RealNetworks has released fixes for this issue.

For RealOne Player and RealOne Player version 2, follow these steps:
1. Select Tools from the menu.
2. Click "Check for Update".
3. Check the box next to "Security Update - March 2003".
4. Click the Install button.

For RealPlayer 8, follow these steps:
1. Select Help from the menu.
2. Click "Check for Update".
3. Check the box next to "Security Update - March 2003".
4. Click the Install button.

RealOne Player for OS X users are advised to download an updated RealOne Player from http://forms.real.com/real/realone/mac.html.

A fix for RealOne Desktop Manager and RealOne Enterprise Desktop is forthcoming.

Users of other versions of RealPlayer and RealOne Player are advised to upgrade to the newest version of RealOne Player, then follow the steps above.

RealPlayer 8 for MacOS users should download the fix below, then follow these steps:
1. Decompress the RP8_Security_March03.sit.hqx archive using Stuffit Expander.
2. Close RealPlayer if it is running.
3. Copy the following update files from the archive to the System Folder:Application Support:Real:Plugins folder:
pxpf60.dll
pxpr60.dll
pxgr60.dll
pxcpng60.dll
httpfsys60.dll
swfrend60.dll


RealNetworks RealPlayer 8.0 Mac

References

RealNetworks RealPlayer PNG Deflate Heap Corruption Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report