Vulnerability Name:

CVE-2005-0755 (CCN-20163)

Assigned:2005-04-19
Published:2005-04-19
Updated:2017-11-21
Summary:Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2005-0755

Source: BUGTRAQ
Type: Third Party Advisory
20050420 RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Overflow

Source: MISC
Type: Third Party Advisory
http://pb.specialised.info/all/adv/real-ram-adv.txt

Source: CCN
Type: RHSA-2005-363
RealPlayer security update

Source: CCN
Type: RHSA-2005-392
HelixPlayer security update

Source: CCN
Type: RHSA-2005-394
RealPlayer security update

Source: CONFIRM
Type: Third Party Advisory
http://service.real.com/help/faq/security/050419_player/EN/

Source: CCN
Type: CIAC INFORMATION BULLETIN P-189
RealNetworks Releases Security Updates

Source: CCN
Type: GLSA-200504-21
RealPlayer, Helix Player: Buffer overflow vulnerability

Source: CCN
Type: RealPlayer Enterprise RAM Web page
WHICH REALPLAYER IS RIGHT FOR YOU?

Source: FEDORA
Type: Third Party Advisory
FEDORA-2005-329

Source: REDHAT
Type: Third Party Advisory
RHSA-2005:363

Source: REDHAT
Type: Third Party Advisory
RHSA-2005:392

Source: REDHAT
Type: Third Party Advisory
RHSA-2005:394

Source: CCN
Type: BID-13264
RealNetworks RealPlayer Enterprise RAM File Parsing Buffer Overflow Vulnerability

Source: CCN
Type: RealPlayer Security Path Update, April 19, 2005
Security Patch Update For Realplayer Enterprise

Source: XF
Type: UNKNOWN
realplayer-enterprise-ram-bo(20163)

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:11205

Source: SUSE
Type: SUSE-SA:2005:026
RealPlayer: buffer overflow in RAM file handling

Vulnerable Configuration:Configuration 1:
  • cpe:/a:realnetworks:helix_player:*:*:*:*:*:*:*:* (Version <= 10.0.3)
  • OR cpe:/a:realnetworks:realone_player:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:8.0:*:*:*:*:mac_os_x:*:*
  • OR cpe:/a:realnetworks:realplayer:8.0:*:*:*:*:unix:*:*
  • OR cpe:/a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:10.0:*:*:de:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:10.0:*:*:en:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:10.0:*:*:ja:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:10.0:beta:*:*:*:*:*:*
  • OR cpe:/a:realnetworks:realplayer:10.0_6.0.12.690:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:11205
    V
    Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.
    2013-04-29
    oval:com.redhat.rhsa:def:20050392
    P
    RHSA-2005:392: HelixPlayer security update (Critical)
    2005-04-20
    BACK
    realnetworks helix player *
    realnetworks realone player 1.0
    realnetworks realone player 2.0
    realnetworks realplayer 8.0
    realnetworks realplayer 8.0
    realnetworks realplayer 8.0
    realnetworks realplayer 10.0
    realnetworks realplayer 10.0
    realnetworks realplayer 10.0
    realnetworks realplayer 10.0
    realnetworks realplayer 10.0 beta
    realnetworks realplayer 10.0_6.0.12.690