CVE-2006-6847
RealPlayer - Denial of Service via RealPlayer.OpenURLInPlayerBrowser Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6847. PoCs published by shinnai.
AI-analyzed exploit summary This exploit targets a denial of service vulnerability in RealPlayer 10.5 by passing excessively long strings to multiple methods in the ierpplug.dll ActiveX control. The PoC demonstrates crashes via GetComponentVersion, HandleAction, and DoAutoUpdateRequest methods.
Description
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.
Exploits (1)
This exploit targets a denial of service vulnerability in RealPlayer 10.5 by passing excessively long strings to multiple methods in the ierpplug.dll ActiveX control. The PoC demonstrates crashes via GetComponentVersion, HandleAction, and DoAutoUpdateRequest methods.