PT-2006-7360 · Realnetworks+1 · Realplayer+1
Shinnai
·
Publicado
2006-12-27
·
Atualizado
2017-10-19
·
CVE-2006-6759
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
RealPlayer version 10.5
Description:
The issue is related to a certain ActiveX control in the rpau3260.dll file, which allows remote attackers to cause a denial of service, resulting in an Internet Explorer crash. This can be achieved by invoking the
RealPlayer.Initialize method with certain arguments.Recommendations:
For RealPlayer version 10.5, consider avoiding the invocation of the
RealPlayer.Initialize method with potentially malicious arguments until a patch is available. As a temporary workaround, restricting the use of the ActiveX control in rpau3260.dll may help minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Realplayer