9.3
CVSSv2

CVE-2005-2922

Published: 31/12/2005 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks helix player 10.0.2

realnetworks helix player 10.0.3

realnetworks helix player 10.0.4

realnetworks realone player 1.0

realnetworks realone player 2.0

realnetworks realplayer 10.0.3

realnetworks realplayer 10.0.4

realnetworks realplayer 10.5_6.0.12.1069

realnetworks realplayer 10.5_6.0.12.1235

realnetworks helix player 10.0.1

realnetworks realone player 0.288

realnetworks realone player 0.297

realnetworks realplayer 10.0.1

realnetworks realplayer 10.0.2

realnetworks realplayer 10.5_6.0.12.1053

realnetworks realplayer 10.5_6.0.12.1056

realnetworks realplayer 10.5_6.0.12.1059

realnetworks helix player 10.0

realnetworks realone player

realnetworks realplayer 10.0.0.305

realnetworks realplayer 10.0.0.331

realnetworks realplayer 10.5

realnetworks realplayer 10.5_6.0.12.1040

realnetworks rhapsody 3.0_build_0.815

realnetworks helix player 10.0.5

realnetworks helix player 10.0.6

realnetworks realplayer

realnetworks realplayer 10.0

realnetworks realplayer 10.0.5

realnetworks realplayer 10.0.6

realnetworks realplayer 8.0

realnetworks rhapsody 3.0

Vendor Advisories

Synopsis RealPlayer security update Type/Severity Security Advisory: Critical Topic An updated RealPlayer package that fixes a format string bug is now availableThis update has been rated as having critical security impact by the Red HatSecurity Response Team Description RealPlayer is a m ...
Synopsis HelixPlayer security update Type/Severity Security Advisory: Critical Topic An updated HelixPlayer package that fixes a string format issue is nowavailableThis update has been rated as having critical security impact by the RedHat Security Response Team Description HelixPlayer is ...