Lucene search

K
freebsdFreeBSDC73305AE-8CD7-11D9-9873-000A95BC6FAE
HistoryMar 01, 2005 - 12:00 a.m.

realplayer -- remote heap overflow

2005-03-0100:00:00
vuxml.freebsd.org
20

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.558

Percentile

97.7%

Two exploits have been identified in the Linux RealPlayer client.
RealNetworks states:

RealNetworks, Inc. has addressed recently discovered
security vulnerabilities that offered the potential for
an attacker to run arbitrary or malicious code on a
customer’s machine. RealNetworks has received no reports
of machines compromised as a result of the now-remedied
vulnerabilities. RealNetworks takes all security
vulnerabilities very seriously.
The specific exploits were:

Exploit 1: To fashion a malicious WAV
file to cause a buffer overflow which could have allowed
an attacker to execute arbitrary code on a customer’s
machine.
Exploit 2: To fashion a malicious
SMIL file to cause a buffer overflow which could have
allowed an attacker to execute arbitrary code on a
customer’s machine.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlinux-realplayer<= 10.0.2UNKNOWN

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.558

Percentile

97.7%

Related for C73305AE-8CD7-11D9-9873-000A95BC6FAE