CVE-2005-3677

RealPlayer 10 and 10.5 - Buffer Overflow via Crafted RealPlayer Skin File

Title source: llm
STIX 2.1

Description

Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15398/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17514
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=113181464921104&w=2

Scores

EPSS 0.0353
EPSS Percentile 87.8%

Details

Status published
Products (7)
realnetworks/realplayer 10.0
realnetworks/realplayer 10.5_6.0.12.1040
realnetworks/realplayer 10.5_6.0.12.1053
realnetworks/realplayer 10.5_6.0.12.1056
realnetworks/realplayer 10.5_6.0.12.1059
realnetworks/realplayer 10.5_6.0.12.1069
realnetworks/realplayer 10.5_6.0.12.1235
Published Nov 18, 2005
Tracked Since Feb 18, 2026