Vulnerability Name: | CVE-2005-1766 (CCN-21129) | ||||||||||||||||
Assigned: | 2005-06-23 | ||||||||||||||||
Published: | 2005-06-23 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file. | ||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-1766 Source: CCN Type: RHSA-2005-517 HelixPlayer security update Source: CCN Type: RHSA-2005-523 RealPlayer security update Source: SECUNIA Type: UNKNOWN 16981 Source: CONFIRM Type: Patch http://service.real.com/help/faq/security/050623_player/EN/ Source: DEBIAN Type: Patch, Vendor Advisory DSA-826 Source: DEBIAN Type: DSA-826 helix-player -- multiple vulnerabilities Source: CCN Type: GLSA-200507-04 RealPlayer: Heap overflow vulnerability Source: CCN Type: iDEFENSE Security Advisory 06.23.05 RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability Source: IDEFENSE Type: Vendor Advisory 20050623 RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability Source: SUSE Type: UNKNOWN SUSE-SA:2005:037 Source: CCN Type: RealPlayer Enterprise Web page RealPlayer Enterprise Source: REDHAT Type: UNKNOWN RHSA-2005:517 Source: REDHAT Type: Vendor Advisory RHSA-2005:523 Source: CCN Type: BID-14048 RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability Source: CCN Type: RealPlayer Security Path Update dated June 23, 2005 Security Patch Update For Realplayer Enterprise Source: XF Type: UNKNOWN realplayer-realmedia-bo(21129) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9509 Source: SUSE Type: SUSE-SA:2005:037 RealPlayer remote buffer overflow | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |