Lucene search

K
gentooGentoo FoundationGLSA-200809-03
HistorySep 04, 2008 - 12:00 a.m.

RealPlayer: Buffer overflow

2008-09-0400:00:00
Gentoo Foundation
security.gentoo.org
16

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.772

Percentile

98.2%

Background

RealPlayer is a multimedia player capable of handling multiple multimedia file formats.

Description

Dyon Balding of Secunia Research reported an unspecified heap-based buffer overflow in the Shockwave Flash (SWF) frame handling.

Impact

By enticing a user to open a specially crafted SWF (Shockwave Flash) file, a remote attacker could be able to execute arbitrary code with the privileges of the user running the application.

Workaround

There is no known workaround at this time.

Resolution

All RealPlayer users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=media-video/realplayer-11.0.0.4028-r1"
OSVersionArchitecturePackageVersionFilename
Gentooanyallmedia-video/realplayer<Β 11.0.0.4028-r1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.772

Percentile

98.2%