Overview
Numerous RealNetworks products do not properly handle chunked data. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable system.
Description
RealNetworks RealPlayer RealNetworks RealPlayer is a multimedia application that allows users to view local and remote audio/video content. |
Impact
By convincing a user to open RealPlayer file hosted on a malicious server, a remote unauthenticated attacker can execute arbitrary code. |
Solution
Patch RealPlayer Apply the patches supplied in the RealNetwork Security Update for March 2006. |
Disable RealPlayer in your web browser
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by iDEFENSE Labs.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2005-2922 |
Severity Metric: | 20.20 |
Date Public: | 2006-03-23 |
Date First Published: | 2006-04-05 |
Date Last Updated: | 2006-05-17 12:45 UTC |
Document Revision: | 33 |