9.3

CVE-2005-2922

Exploit
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Realnetworks ≫ Helix Player Version 10.0 Edition linux
Realnetworks ≫ Helix Player Version 10.0.1 Edition linux
Realnetworks ≫ Helix Player Version 10.0.2 Edition linux
Realnetworks ≫ Helix Player Version 10.0.3 Edition linux
Realnetworks ≫ Helix Player Version 10.0.4 Edition linux
Realnetworks ≫ Helix Player Version 10.0.5 Edition linux
Realnetworks ≫ Helix Player Version 10.0.6 Edition linux
Realnetworks ≫ Realone Player Version 0.288 Edition mac_os_x
Realnetworks ≫ Realone Player Version 0.297 Edition mac_os_x
Realnetworks ≫ Realone Player Version 1.0
Realnetworks ≫ Realone Player Version 2.0
Realnetworks ≫ Realplayer Edition enterprise
Realnetworks ≫ Realplayer Version 8.0 Edition win32
Realnetworks ≫ Realplayer Version 10.0
Realnetworks ≫ Realplayer Version 10.0.0.305 Edition mac_os
Realnetworks ≫ Realplayer Version 10.0.0.331 Edition mac_os
Realnetworks ≫ Realplayer Version 10.0.1 Edition linux
Realnetworks ≫ Realplayer Version 10.0.2 Edition linux
Realnetworks ≫ Realplayer Version 10.0.3 Edition linux
Realnetworks ≫ Realplayer Version 10.0.4 Edition linux
Realnetworks ≫ Realplayer Version 10.0.5 Edition linux
Realnetworks ≫ Realplayer Version 10.0.6 Edition linux
Realnetworks ≫ Realplayer Version 10.5
Realnetworks ≫ Realplayer Version 10.5_6.0.12.1040
Realnetworks ≫ Realplayer Version 10.5_6.0.12.1053
Realnetworks ≫ Realplayer Version 10.5_6.0.12.1056
Realnetworks ≫ Realplayer Version 10.5_6.0.12.1059
Realnetworks ≫ Realplayer Version 10.5_6.0.12.1069
Realnetworks ≫ Realplayer Version 10.5_6.0.12.1235
Realnetworks ≫ Rhapsody Version 3.0
Realnetworks ≫ Rhapsody Version 3.0_build_0.815
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.78% 0.921
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.redhat.com/support/errata/RHSA-2005-762.html
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-788.html
Patch
Vendor Advisory
http://secunia.com/advisories/19358
Vendor Advisory
http://www.service.real.com/realplayer/security/03162006_player/en/
Patch
http://www.vupen.com/english/advisories/2006/1057
Vendor Advisory
http://secunia.com/advisories/19365
Patch
Vendor Advisory
http://securitytracker.com/id?1015808
http://www.kb.cert.org/vuls/id/172489
Patch
Third Party Advisory
US Government Resource
http://www.novell.com/linux/security/advisories/2006_18_realplayer.html
Patch
Vendor Advisory
http://www.securityfocus.com/bid/17202
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/25409
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11444