Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 10-010

Zero Day Initiative Advisory 10-010 – This vulnerability allows remote attackers to execute code on vulnerable installations of RealNetworks RealPlayer. User interaction is required in that a user must visit a malicious website or open a malicious file and accept a dialog to switch player skins. The specific flaw exists during parsing of malformed RealPlayer .RJS skin files. While loading a skin the application copies certain variable length fields from the extracted file named web.xmb into a statically sized buffer. By crafting these fields appropriately an attack can cause the process to overflow the buffer. This can be leveraged to execute arbitrary code with the privileges of the application.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/85513/ZDI-10-010.txt

Source: https://packetstormsecurity.com/files/85513/Zero-Day-Initiative-Advisory-10-010.html

Related posts
Advisories

57657.html

Advisories

Secunia Security Advisory 17317

Advisories

Ubuntu Security Notice 284-1

Advisories

Hardened-PHP Project Security Advisory 2006-14.139