Get a Pentest and security assessment of your IT network.

Advisories

eEye.vidplin.txt

eEye Security Advisory – eEye Digital Security has discovered a critical vulnerability in RealPlayer. The vulnerability allows a remote attacker to reliably overwrite heap memory with arbitrary data and execute arbitrary code in the context of the user who executed the player. This specific flaw exists within the vidplin.dll file used by RealPlayer. By specially crafting a malformed .avi movie file, a direct heap overwrite is triggered, and reliable code execution is then possible. This vulnerability can be trigger when a user views a webpage, or opens an .avi file via email, instant messenger, or other common file transfer programs.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/38266/eEye.vidplin.txt

Source: https://packetstormsecurity.com/files/38266/eEye.vidplin.txt.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18729

Advisories

Debian Linux Security Advisory 1144-1

Advisories

Mandriva Linux Security Advisory 2007.062