[NEWS] REAL One Player R3T File Format Stack Overflow

From: SecuriTeam (support_at_securiteam.com)
Date: 04/08/04

  • Next message: SecuriTeam: "[UNIX] KAME IKE Daemon Racoon Fails to Verify RSA Signatures"
    To: list@securiteam.com
    Date: 8 Apr 2004 11:53:44 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      REAL One Player R3T File Format Stack Overflow
    ------------------------------------------------------------------------

    SUMMARY

    RealOne / RealPlayer is one of the most widely used products for Internet
    media delivery. There are currently in excess of 200 million users
    worldwide of these products.

    By crafting malformed .R3T file it is possible to cause a stack based
    overruns in RealPlayer / RealOne Player. By forcing a browser to a
    website containing such a file, code could be executed on the target
    machine running in the context of the logged on user, alternatively the
    end user would be required to open the .R3T file as a mail attachment.

    DETAILS

    Vulnerable Systems:
     * RealPlayer 8
     * RealOne Player
     * RealOne Player v2 for Windows only (all languages)
     * RealPlayer 10 Beta (English only)
     * ReaPlayer Enterprise (all versions, standalone and as configured by the
    RealPlayer Enterprise Manager)

    Fix Information:
    For the various fix options available for different types of REAL
    products, NGS suggest visiting
    <http://service.real.com/help/faq/security/040406_r3t/en/>
    http://service.real.com/help/faq/security/040406_r3t/en/ for detailed
    information.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:mark@ngssoftware.com> Mark
    Litchfield.

    The original article can be found at:
    <http://www.ngssoftware.com/advisories/realr3t.txt>
    http://www.ngssoftware.com/advisories/realr3t.txt.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] KAME IKE Daemon Racoon Fails to Verify RSA Signatures"

    Relevant Pages

    • [UNIX] RealNetworks RealPlayer and Helix Player Invalid Chunk Size Heap Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... RealNetworks RealPlayer and Helix Player Invalid Chunk Size Heap Overflow ... The vulnerability specifically exists in the handling of the 'chunked' ...
      (Securiteam)
    • [NT] RealPlayer vidplin.dll AVI Processing Heap Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in RealPlayer for Windows allows a remote attacker to ... reliably overwrite heap memory with arbitrary data and execute arbitrary ... RealPlayer calls upon a specific DLL, vidplin.dll, where the vulnerability ...
      (Securiteam)
    • [NT] Directory Traversal In RealPlayer Allows Code Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... * RealPlayer 10 Beta ... The RMP file may contain references to a number of files as tags. ... An attacker may use "..\" sequences in the file name to cause the skin ...
      (Securiteam)
    • [NT] RealPlayer Miscellaneous Vulnerabilities (RMP, RJS)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Two vulnerabilities have been discovered in RealPlayer that potentially be ... the Real Metadata Package File Deletion vulnerability to reliably delete ... the file name to break out of the download directory, ...
      (Securiteam)
    • [NT] RealPlayer embd3260.dll Error Response Heap Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The vulnerability allows a remote attacker to reliably ... This specific flaw exists within the embd3260.dll file used by RealPlayer. ... direct heap overwrite is triggered, and reliable code execution is then ...
      (Securiteam)