CVE-2005-0611

RealPlayer and RealOne Player - Heap-Based Buffer Overflow via WAV File

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-271.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11419
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-265.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110979465912834&w=2
Mailing List mailing-list x_refsource_vulnwatch
http://marc.info/?l=vulnwatch&m=110977858619314&w=2

Scores

EPSS 0.0475
EPSS Percentile 89.6%

Details

Status published
Products (7)
realnetworks/helix_player
realnetworks/realone_player 1.0
realnetworks/realone_player 2.0
realnetworks/realplayer
realnetworks/realplayer 8.0
realnetworks/realplayer 10.0
realnetworks/realplayer 10.5
Published May 02, 2005
Tracked Since Feb 18, 2026