EEYEB20050510Third-party advisory
http://marc.info/?l=bugtraq&m=113166476423021&w=2 CVE-2005-2629
RealNetworks RealOne Player/RealPlayer - '.RM' Local Stack Buffer Overflow
Record summary
CVE-2005-2629 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.
Description
Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRealNetworks RealOne Player/RealPlayer - '.RM' Local Stack Buffer OverflowExploitDB exploitby nolimitNot analyzed1 file
References
Showing 12 of 1517514Third-party advisory
http://secunia.com/advisories/17514 17559Third-party advisory
http://secunia.com/advisories/17559 17860Third-party advisory
http://secunia.com/advisories/17860 169Third-party advisory
http://securityreason.com/securityalert/169 1015184vdb entry
http://securitytracker.com/id?1015184 1015185vdb entry
http://securitytracker.com/id?1015185 1015186vdb entry
http://securitytracker.com/id?1015186 service.real.comConfirmation
http://service.real.com/help/faq/security/051110_player/EN DSA-915Vendor advisory
http://www.debian.org/security/2005/dsa-915 AD20051110aThird-party advisory
http://www.eeye.com/html/research/advisories/AD20051110a.html 15381vdb entry
http://www.securityfocus.com/bid/15381