CVE-2004-0387

RealOne Player - Stack-based Buffer Overflow via Malformed .R3T File

Title source: llm
STIX 2.1

Description

Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/displayvuln.php?osvdb_id=4977
Patch, Vendor Advisory x_refsource_confirm
http://www.service.real.com/help/faq/security/040406_r3t/en/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108135350810135&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15774
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0077.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11314
Patch, Vendor Advisory x_refsource_misc
http://www.ngssoftware.com/advisories/realr3t.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10070

Scores

EPSS 0.0629
EPSS Percentile 91.0%

Details

Status published
Products (3)
realnetworks/realone_player (2 CPE variants)
realnetworks/realone_player 10_beta
realnetworks/realplayer 8.0
Published Jun 01, 2004
Tracked Since Feb 18, 2026