what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

realr3t.txt

realr3t.txt
Posted Apr 7, 2004
Authored by Mark Litchfield | Site ngssoftware.com

NGSSoftware Insight Security Research Advisory #NISR17042004 - By crafting malformed .R3T file it is possible to cause a stack based overruns in RealPlayer / RealOne Player. By forcing a browser to a website containing such a file, code could be executed on the target machine running in the context of the logged on user, alternatively the end user would be required to open the .R3T file as a mail attachment. Systems Affected: RealPlayer 8, RealOne Player, RealOne Player v2 for Windows only (all languages), RealPlayer 10 Beta (English only) and RealPlayer Enterprise (all versions, stand-alone and as configured by the RealPlayer Enterprise Manager).

tags | advisory, overflow
systems | windows
SHA-256 | 6d743136e2278e3913a2b15ed69ed2788f1f4b991aaed8aef0dce1951f4208cf

realr3t.txt

Change Mirror Download
NGSSoftware Insight Security Research Advisory

Name: REAL One Player R3T File Format Stack Overflow
Systems Affected: RealPlayer 8, RealOne Player, RealOne Player v2 for
Windows only (all languages), RealPlayer 10 Beta (English only) and
ReaPlayer Enterprise (all versions, standalone and as configured by the
RealPlayer Enterprise Manager).
Severity: High (If RT3 Plugin Present Within installed REAL Player)
Vendor URL: http://www.real.com
Author: Mark Litchfield [ mark@ngssoftware.com ]
Date Vendor Notified: 4th February 2004
Date of Public Advisory: 7th April 2004
Advisory number: #NISR17042004
Advisory URL: http://www.ngssoftware.com/advisories/realr3t.txt

Description
***********

RealOne / RealPlayer is one of the most widely used products for internet
media delivery. There are currently in excess of 200 million users worlwide
of these products.

Details
*******

By crafting malformed .R3T file it is possible to cause a stack based
overruns in RealPlayer / RealOne Player. By forcing a browser to a website
containing such a file, code could be exectued on the target machine running
in the context of the logged on user, alternatively the end user would be
required to open the .R3T file as a mail attachment.

Fix Information
***************

For the various fix options available for different types of REAL products,
NGS suggest visiting
http://service.real.com/help/faq/security/040406_r3t/en/ for detailed
information

About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

http://www.ngssoftware.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com

Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close