PT-2005-2994 · Realnetworks · Realone Player+2

Flashsky

·

Publicado

2005-06-26

·

Atualizado

2016-10-18

·

CVE-2005-2052

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: RealPlayer versions 6.0.12.1040 through 1069 RealOne Player versions 1 and 2 RealPlayer version 8 RealPlayer Enterprise (affected versions not specified)
Description: The issue is related to a heap-based buffer overflow in the vidplin.dll component. This can be exploited by remote attackers through a specially crafted .avi file with a modified strf structure value, potentially allowing the execution of arbitrary code.
Recommendations: For RealPlayer versions 6.0.12.1040 through 1069, update to a version outside of this range to resolve the issue. For RealOne Player versions 1 and 2, consider upgrading to a newer version of the player. For RealPlayer version 8, update to a newer version of RealPlayer. For RealPlayer Enterprise, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2052

Produtos afetados

Realone Player
Realplayer
Realplayer Enterprise