Secunia Logo
 
RealPlayer Playlist Handling Buffer Overflow Vulnerability
Secunia Advisory: SA27248
Release Date: 2007-10-22
Last Update: 2007-10-23
Popularity: 14,649 views

Critical:
Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:RealOne Player 1.x
RealOne Player 2.x
RealPlayer 10.x

Binary Analysis: BA257 :: Available for 1 Credit

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-5601


Description:
A vulnerability has been discovered in RealPlayer, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a signedness error in MPAMedia.dll when handling playlist names. This can be exploited to cause a stack-based buffer overflow by e.g. importing a file into a specified playlist with an overly long name via the "Import()" method of the IERPCtl ActiveX control (ierpplug.dll).

Successful exploitation allows execution of arbitrary code.

NOTE: The vulnerability is currently being actively exploited.

Solution:
Apply patch for RealPlayer 10.5 and 11 beta:
http://service.real.com/realplayer/security/191007_player/en/securitydb.rnx

The vendor recommends users of RealPlayer 10 and RealOne v1 and v2 to upgrade to version 10.5 and apply the patch.

NOTE: According to the vendor, RealPlayer 8 and prior versions for Windows are not affected. Versions for Macintosh and Linux are also not affected.

Provided and/or discovered by:
Reported as a 0-day.

Changelog:
2007-10-23: Added additional link in "Original Advisory" section.

Original Advisory:
RealNetworks:
http://service.real.com/realplayer/security/191007_player/en/
http://docs.real.com/docs/security/SecurityUpdate101907Player.pdf

Other References:
US-CERT VU#871673:
http://www.kb.cert.org/vuls/id/871673

Extended Solution:
The "Extended Solution" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 1
New vulnerabilities: 1
Updated advisories: 1


1st Dec, 2008
New advisories: 33
New vulnerabilities: 55
Updated advisories: 56


Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 55 views
2. Sun Java JDK / JRE Multiple Vulnerabilities // 41 views
3. Microsoft Office Communications Server SIP INVITE Denial of Service // 36 views
4. Basic PHP CMS "id" SQL Injection Vulnerability // 31 views
5. Lito Lite CMS "cid" SQL Injection Vulnerability // 28 views
6. RakhiSoftware Shopping Cart Multiple Vulnerabilities // 27 views
7. Active eWebquiz "useremail" and "password" SQL Injection Vulnerabilities // 24 views
8. Bluo CMS "id" SQL Injection Vulnerability // 24 views
9. Minimal Ablog Multiple Vulnerabilities // 23 views
10. Quagga Multiple Denial of Service Vulnerabilities // 23 views