vendor:
RealPlayer
by:
suto
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: RealPlayer
Affected Version From: RealPlayer <=15.0.6.14
Affected Version To: RealPlayer 15.0.5.109
Patch Exists: YES
Related CWE: CVE-2012-5691
CPE: a:realnetworks:realplayer:15.0.5.109
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2012
RealPlayer RealMedia File Handling Buffer Overflow
This module exploits a stack based buffer overflow on RealPlayer <=15.0.6.14. The vulnerability exists in the handling of real media files, due to the insecure usage of the GetPrivateProfileString function to retrieve the URL property from an InternetShortcut section. This module generates a malicious rm file which must be opened with RealPlayer via drag and drop or double click methods. It has been tested successfully on Windows XP SP3 with RealPlayer 15.0.5.109.
Mitigation:
Upgrade to the latest version of RealPlayer