7.5
CVSSv2

CVE-2002-1014

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote malicious users to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realjukebox 2 1.0.2.340

realnetworks realjukebox 2 plus 1.0.2.340

realnetworks realone player 6.0.10.505

realnetworks realjukebox 2 1.0.2.379

realnetworks realjukebox 2 plus 1.0.2.379

Exploits

source: wwwsecurityfocuscom/bid/5217/info Real Software has announced a vulnerability in RealJukebox2 and Real Player Gold A buffer overflow condition exists due to insufficient bounds checking of fields in skinfiles There is an unchecked buffer for the "CONTROLnImage" field of the "skinini" file By supplying an overly long filename ...