CVE-2013-7260
RealNetworks RealPlayer <17.0.4.61 - Windows/Mac - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2013-7260.
PoCs published by Gabor Seljan, including Metasploit module exploits/windows/fileformat/realplayer_ver_attribute_bof.
AI-analyzed exploit summary This exploit leverages a buffer overflow in RealNetworks RealPlayer (CVE-2013-7260) via a malformed RMP file to achieve remote code execution. It uses ROP gadgets and shellcode to bypass DEP and execute arbitrary code (e.g., calc.exe).
Description
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877.
Exploits (2)
This exploit leverages a buffer overflow in RealNetworks RealPlayer (CVE-2013-7260) via a malformed RMP file to achieve remote code execution. It uses ROP gadgets and shellcode to bypass DEP and execute arbitrary code (e.g., calc.exe).
This Metasploit module exploits a stack-based buffer overflow in RealNetworks RealPlayer versions 16.0.3.51 and 16.0.2.32 via a malformed XML declaration in an .RMP file. It uses ROP gadgets to bypass DEP and execute arbitrary payloads.