Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> RealPlayer multiple remote overflows


Vulnerability Assessment Details

RealPlayer multiple remote overflows

Vulnerability Assessment Summary
Acertains the version of RealPlayer

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote Windows application is affected by several remote
overflows.

Description :

According to its version number, the installed version of RealPlayer
on the remote host is vulnerable to several overflows. In exploiting
these flaws, a possible hacker would need to be able to coerce a local user
into visiting a malicious URL or downloading a malicious media file
which, upon execution, would execute code with the rights of the
local user.

See also :

http://www.securityfocus.com/archive/1/365709/2004-06-07/2004-06-13/0
http://www.idefense.com/application/poi/display?id=109&type=vulnerabilities
http://service.real.com/help/faq/security/040610_player/EN/
http://www.eeye.com/html/research/upcoming/20040811.html

Solution :

Unknown at this time.

Network Security Threat Level:

High / CVSS Base Score : 7
(AV:R/AC:L/Au:NR/C:P/A:P/I:P/B:N)

Networks Security ID: 10527, 10528, 10934

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors

Dell PowerEdge M620 Blade. 1 x E5-2650, 1 x 500GB, SATA Backplane, 8GB Ram
$350.0
Dell PowerEdge M620 Blade. 1 x E5-2650, 1 x 500GB, SATA Backplane, 8GB Ram pictureCRAY Jaguar​/Titan 128-Core XK6 X6 Blade Supercomputer Super Computer
$900.0
CRAY Jaguar​/Titan 128-Core XK6 X6 Blade Supercomputer Super Computer pictureGenuine HP - AD399-60009 - HDD Backplane for BL860C I2 Blade Server
$50.0
Genuine HP - AD399-60009 - HDD Backplane for BL860C I2 Blade Server picture1pcs Blade Server 3.5" Hard Drive Tray Caddy Sled Bracket For HP SAS Set
$3.81
1pcs Blade Server 3.5


Discussions

No Discussions have been posted on this vulnerability.