Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


Return to article

Arbitrary Code Execution Vulnerability in RealPlayer
 

Reported October 01, 2004, by eEye Digital Security

VERSIONS AFFECTED

  • RealPlayer 10.5 (6.0.12.1040 and earlier)
  • RealPlayer 10
  • RealPlayer 8 (Local Playback)
  • RealOne Player V2, V1

 

DESCRIPTION
A vulnerability in RealPlayer could let a remote attacker reliably overwrite heap memory with arbitrary data and execute arbitrary code within the user security context. This specific flaw exists within the pnen3260.dll file that RealPlayer uses. By specially crafting a malformed .rm movie file along with a Synchronized Multimedia Integration Language (SMIL) file, a direct heap overwrite is triggered and reliable code execution is then possible.

VENDOR RESPONSE
RealNetworks has released has released a patch for this vulnerability, which is also available via the Updates section of the affected application.

CREDIT
Discovered by eEye Digital Security.







Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement