Vulnerability Name: | CVE-2010-0416 (CCN-56427) | ||||||||||||||||
Assigned: | 2010-01-19 | ||||||||||||||||
Published: | 2010-01-19 | ||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||
Summary: | Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-0416 Source: MLIST Type: Exploit [common-cvs] 20070703 util hxurl.cpp,1.24.4.1,1.24.4.1.4.1 Source: CCN Type: Helix Player Community Web page util rlstate.cpp Source: CCN Type: RHSA-2010-0094 Critical: HelixPlayer security update Source: SECUNIA Type: UNKNOWN 38450 Source: CCN Type: OSVDB ID: 62469 RealNetworks Multiple Products xcommon/util/hxurl.cpp Unescape Function Overflow Source: CCN Type: OSVDB ID: 62470 RealNetworks Multiple Products player/hxclientkit/src/CHXClientSink.cpp Unescape Function Overflow Source: CCN Type: RealPlayer Web site RealPlayer Source: REDHAT Type: UNKNOWN RHSA-2010:0094 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=561856 Source: XF Type: UNKNOWN helix-realplayer-unescape-bo(56427) Source: CONFIRM Type: UNKNOWN https://helixcommunity.org/viewcvs/common/util/hxurl.cpp?view=log#rev1.24.4.1.4.1 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10847 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |