RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e)

From: NGSSoftware Insight Security Research (nisr_at_NEXTGENSS.COM)
Date: 01/19/05

  • Next message: NGSSoftware Insight Security Research: "Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)"
    Date:         Wed, 19 Jan 2005 16:58:57 -0000
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    NGSSoftware Insight Security Research Advisory

    Name: RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability
    Systems Affected: RealPlayer 10.5 (6.0.12.1040) and older
    Severity: High
    Vendor URL: http://www.real.com/
    Author: John Heasman [ john@ngssoftware.com ]
    Date of Public Advisory: 19th January 2004
    Advisory number: #NISR19012005e
    Advisory URL: http://www.ngssoftware.com/advisories/real-01full.txt
    Reference: http://www.ngssoftware.com/advisories/real-01.txt

    Description
    ***********

    A vulnerability has been discovered in the RealPlayer ActiveX component
    which can allow remote code execution when visiting a specially crafted
    webpage or when opening a specially crafted skin file.

    Details
    *******

    The RealPlayer ActiveX component exports a function called HandleAction().
    This function is designed to take a method or an action, and to execute it
    under a number of differing environments. This could be within a
    RealPlayer skin file or a webpage which is designed to interact with
    RealPlayer.

    One of the 'actions' which HandleAction() will accept is
    'ShowPreferences'. This method will accept two arguments, a category and
    the url of it's respective webpage.

    It has been discovered that passing overly long arguments to this method
    will result in an unbounded concatenation of the two arguments into a
    stack based buffer through an unchecked call to sprintf().

    Fix Information
    ***************

    RealNetworks have released an update for the ShowPreferences buffer
    overflow which can be downloaded from:

    http://service.real.com/help/faq/security/040928_player/EN/

    A check for this vulnerability has been added to Typhon III, NGSSoftware's
    advanced vulnerability assessment scanner. For more information please
    visit the NGSSoftware website at http://www.ngssoftware.com/

    About NGSSoftware
    *****************

    NGSSoftware design, research and develop intelligent, advanced application
    security assessment scanners. Based in the United Kingdom, NGSSoftware
    have offices in the South of London and the East Coast of Scotland.
    NGSSoftware's sister company NGSConsulting, offers best of breed security
    consulting services, specialising in application, host and network
    security assessments.

    http://www.ngssoftware.com/

    Telephone +44 208 401 0070
    Fax +44 208 401 0076

    enquiries@ngssoftware.com

    --
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
    --
    

  • Next message: NGSSoftware Insight Security Research: "Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)"

    Relevant Pages