what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

NGSrealone.txt

NGSrealone.txt
Posted Feb 5, 2004
Authored by Mark Litchfield | Site ngssoftware.com

NGSSoftware Insight Security Research Advisory #NISR04022004a - By crafting malformed .RP, .RT, .RAM, .RPM or .SMIL file, it is possible to cause heap and stack based overruns in RealPlayer / RealOne Player.

tags | advisory, overflow
SHA-256 | 08c196447e2192d2c612710832b2422a990dbc5bd70ac8d47941a572f399a72a

NGSrealone.txt

Change Mirror Download
NGSSoftware Insight Security Research Advisory

Name: RealPlayer & RealOne Player Buffer Overruns
Systems Affected: RealOne Player, RealOne Player v2, RealOne Enterprise
Desktop / RealPlayer Enterprise (all language versions, all platforms)
Severity: High Risk
Vendor URL: http://www.real.com/
Author: Mark Litchfield [ mark@ngssoftware.com ]
Date Vendor Notified: 23rd Dec 2003
Date of Public Advisory: 4th February 2004
Advisory number: #NISR04022004a
Advisory URL: http://www.ngssoftware.com/advisories/realone.txt

Description
***********
RealOne / RealPlayer is one of the most widely used products for internet
media delivery. There are currently in excess of 200 million users worlwide
of these products.

Details
*******

By crafting malformed .RP, .RT, .RAM, .RPM & .SMIL files it is possible to
cause heap and stack based overruns in RealPlayer / RealOne Player. By
forcing a browser to a website containing such a file, code could be
exectued on the target machine running in the context of the logged on user,
alternatively the end user would be required to open the attachment (except
in the case of the .RPM file)

Fix Information
***************

REAL have supplied a patch for this and other problems discovered by Jouko
Pynnönen and can be downloaded from REAL's website. Detailed below is
REAL's instruction listed in their own advisory found at
http://service.real.com/help/faq/security/040123_player/EN/ to remediate
these issues.

RealOne Player, RealOne Player v2 (localized languages) and RealPlayer 10
Beta customers please use the following steps to update your Player:

* In the Tools menu select Check for Update.
* Select the box next to the "RealPlayer 10" (English) or "RealOne Player"
(localized) component.
* Click the Install button to download and install the update.

RealPlayer 8 (version 6.0.9.584):

* Go to the Help menu.
* Select "Check for Update".
* Select the box next to the "RealPlayer 10" (English) or "RealOne Player"
(localized) component.
* Click the Install button to download and install the update.


About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

http://www.ngssoftware.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com



Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    6 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close