Lucene search

K
cve[email protected]CVE-2003-0141
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2003-0141

2003-04-0205:00:00
web.nvd.nist.gov
19
realone player
realplayer
png
deflate algorithm
remote attackers
heap corruption
memory overwrite
graphic file

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%

The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.

Affected configurations

NVD
Node
realnetworksrealone_enterprise_desktopMatch6.0.11.774
OR
realnetworksrealone_playerMatch2.0
OR
realnetworksrealone_playerMatch6.0.10.505gold
OR
realnetworksrealone_playerMatch6.0.11.818
OR
realnetworksrealone_playerMatch6.0.11.830
OR
realnetworksrealone_playerMatch6.0.11.841
OR
realnetworksrealone_playerMatch6.0.11.853
OR
realnetworksrealone_playerMatch9.0.0.288
OR
realnetworksrealone_playerMatch9.0.0.297
OR
realnetworksrealplayerMatch8.0

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%

Related for CVE-2003-0141