HTTP: RealNetworks RealPlayer AVI Parsing Buffer Overflow
This signature detects attempts to exploit a known vulnerability against RealNetworks Realplayer. Attacker can create a malicious Web site, containing dangerous AVI files, which if accessed by a victim, allows the attacker to gain control of victim's computer.
Extended Description
Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf structure value.
Affected Products
Realnetworks realplayer
References
BugTraq: 13530
CVE: CVE-2005-2052
URL: http://service.real.com/help/faq/security/050623_player/EN/
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Realnetworks
5.1