what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

realr3t.txt

realr3t.txt
Posted Apr 7, 2004
Authored by Mark Litchfield | Site ngssoftware.com

NGSSoftware Insight Security Research Advisory #NISR17042004 - By crafting malformed .R3T file it is possible to cause a stack based overruns in RealPlayer / RealOne Player. By forcing a browser to a website containing such a file, code could be executed on the target machine running in the context of the logged on user, alternatively the end user would be required to open the .R3T file as a mail attachment. Systems Affected: RealPlayer 8, RealOne Player, RealOne Player v2 for Windows only (all languages), RealPlayer 10 Beta (English only) and RealPlayer Enterprise (all versions, stand-alone and as configured by the RealPlayer Enterprise Manager).

tags | advisory, overflow
systems | windows
SHA-256 | 6d743136e2278e3913a2b15ed69ed2788f1f4b991aaed8aef0dce1951f4208cf

realr3t.txt

Change Mirror Download
NGSSoftware Insight Security Research Advisory

Name: REAL One Player R3T File Format Stack Overflow
Systems Affected: RealPlayer 8, RealOne Player, RealOne Player v2 for
Windows only (all languages), RealPlayer 10 Beta (English only) and
ReaPlayer Enterprise (all versions, standalone and as configured by the
RealPlayer Enterprise Manager).
Severity: High (If RT3 Plugin Present Within installed REAL Player)
Vendor URL: https://www.real.com
Author: Mark Litchfield [ mark@ngssoftware.com ]
Date Vendor Notified: 4th February 2004
Date of Public Advisory: 7th April 2004
Advisory number: #NISR17042004
Advisory URL: https://www.ngssoftware.com/advisories/realr3t.txt

Description
***********

RealOne / RealPlayer is one of the most widely used products for internet
media delivery. There are currently in excess of 200 million users worlwide
of these products.

Details
*******

By crafting malformed .R3T file it is possible to cause a stack based
overruns in RealPlayer / RealOne Player. By forcing a browser to a website
containing such a file, code could be exectued on the target machine running
in the context of the logged on user, alternatively the end user would be
required to open the .R3T file as a mail attachment.

Fix Information
***************

For the various fix options available for different types of REAL products,
NGS suggest visiting
https://service.real.com/help/faq/security/040406_r3t/en/ for detailed
information

About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

https://www.ngssoftware.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close