SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities


Arrow  SecurityAlert : 690
Arrow  CVE : CVE-2006-0323
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : Yes
Arrow  Exploit Available : No
Arrow  Credit : Sowhat
Arrow  Published : 12.04.2006

Arrow  Affected Software : Windows
RealPlayer 8
RealOne Player & RealOne Player V2
RealPlayer 10
RealPlayer 10.5

Macintosh
RealOne Player
RealPlayer 10

Linux
RealPlayer 10



Arrow  Advisory Content :  

Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities

By Sowhat of Nevis Labs
Date: 2006.03.22

http://www.nevisnetworks.com
http://secway.org/advisory/AD20060322.txt

CVE: CVE-2006-0323
US CERT: VU#231028

Vendor
RealNetworks Inc.

Products affected:

Windows
RealPlayer 8
RealOne Player & RealOne Player V2
RealPlayer 10
RealPlayer 10.5

Macintosh
RealOne Player
RealPlayer 10

Linux
RealPlayer 10

Overview:

RealPlayer is an application for playing various media formats,
developed by RealNetworks Inc. For more information, visit
http://www.real.com/.

Details:

There are multiple vulnerabilities found in swfformat.dll.
A carefully crafted .swf file may execute arbitrary code or crash the
RealPlayer.

By persuading a user to access a specially crafted SWF file with
RealPlayer,
a remote attacker may be able to execute arbitrary code.
And also, these vulnerabilities can be triggered remotely through ActiveX
in IE.

By setting the size of SWF files to a value smaller than the actual size,
you can trigger one of the vulnerabilities.

Actually, there are multiple holes that have been fixed in swfformat.dll.

POC:

No PoC will be released for this.

FIX:

http://service.real.com/realplayer/security/03162006_player/en/

Vendor Response:

2005.10.07 Vendor notified via email
2005.10.07 Vendor responded
2005.03.22 Patch released
2006.04.11 Advisory released

Common Vulnerabilities and Exposures (CVE) Information:

The Common Vulnerabilities and Exposures (CVE) project has assigned
the following names to these issues. These are candidates for
inclusion in the CVE list (http://cve.mitre.org), which standardizes
names for security problems.

CVE-2006-0323

Greetings to Paul Gese (at) real (dot) com [email concealed], Chi, OYXin,
Narasimha Datta and all
Nevis Labs guys.

References:

1. http://service.real.com/realplayer/security/03162006_player/en/
2. http://www.kb.cert.org/vuls/id/231028
3. http://www.macromedia.com/licensing/developer/fileformat/faq/
4. http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0323
5. http://www.gentoo.org/security/en/glsa/glsa-200603-24.xml
6. http://www.novell.com/linux/security/advisories/2006_18_realplayer.html
7. http://secunia.com/advisories/19358/

--
Sowhat
http://secway.org
"Life is like a bug, Do you know how to exploit it ?"





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

» PHP 5.3.0 5.2.11
   posix_mkfifo()
   open_basedir bypass

Copyright © SecurityReason.com. All Rights Reserved.