PT-2005-2736 · Realnetworks+1 · Realplayer+1
Published
2005-06-23
·
Updated
2017-10-11
·
CVE-2005-1766
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RealPlayer versions 10.5 6.0.12.1056 and earlier on Windows
RealPlayer versions prior to 10.0.5 on Linux
Description
The issue is related to a heap-based buffer overflow in the rtffplin.cpp component. It can be triggered by a RealMedia file containing a long RealText string, such as an SMIL file, allowing remote attackers to execute arbitrary code.
Recommendations
For RealPlayer version 10.5 6.0.12.1056 on Windows, update to a version later than 10.5 6.0.12.1056.
For RealPlayer versions prior to 10.0.5 on Linux, update to version 10.0.5 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realplayer
Red Hat