CVE-2008-1309

The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.
References
Link Resource
http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html
http://secunia.com/advisories/29315 Vendor Advisory
http://service.real.com/realplayer/security/07252008_player/en/ Vendor Advisory
http://www.kb.cert.org/vuls/id/831457 US Government Resource
http://www.securityfocus.com/archive/1/494779/100/0/threaded
http://www.securityfocus.com/bid/28157 Exploit
http://www.securitytracker.com/id?1019576
http://www.securitytracker.com/id?1020563
http://www.vupen.com/english/advisories/2008/0842 Vendor Advisory
http://www.vupen.com/english/advisories/2008/2194/references Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-047/
https://exchange.xforce.ibmcloud.com/vulnerabilities/41087
https://www.exploit-db.com/exploits/5332
http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html
http://secunia.com/advisories/29315 Vendor Advisory
http://service.real.com/realplayer/security/07252008_player/en/ Vendor Advisory
http://www.kb.cert.org/vuls/id/831457 US Government Resource
http://www.securityfocus.com/archive/1/494779/100/0/threaded
http://www.securityfocus.com/bid/28157 Exploit
http://www.securitytracker.com/id?1019576
http://www.securitytracker.com/id?1020563
http://www.vupen.com/english/advisories/2008/0842 Vendor Advisory
http://www.vupen.com/english/advisories/2008/2194/references Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-047/
https://exchange.xforce.ibmcloud.com/vulnerabilities/41087
https://www.exploit-db.com/exploits/5332
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:realnetworks:realplayer:*:*:enterprise:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11:*:*:*:*:*:*:*

History

21 Nov 2024, 00:44

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html -
References () http://secunia.com/advisories/29315 - Vendor Advisory () http://secunia.com/advisories/29315 - Vendor Advisory
References () http://service.real.com/realplayer/security/07252008_player/en/ - Vendor Advisory () http://service.real.com/realplayer/security/07252008_player/en/ - Vendor Advisory
References () http://www.kb.cert.org/vuls/id/831457 - US Government Resource () http://www.kb.cert.org/vuls/id/831457 - US Government Resource
References () http://www.securityfocus.com/archive/1/494779/100/0/threaded - () http://www.securityfocus.com/archive/1/494779/100/0/threaded -
References () http://www.securityfocus.com/bid/28157 - Exploit () http://www.securityfocus.com/bid/28157 - Exploit
References () http://www.securitytracker.com/id?1019576 - () http://www.securitytracker.com/id?1019576 -
References () http://www.securitytracker.com/id?1020563 - () http://www.securitytracker.com/id?1020563 -
References () http://www.vupen.com/english/advisories/2008/0842 - Vendor Advisory () http://www.vupen.com/english/advisories/2008/0842 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2008/2194/references - Vendor Advisory () http://www.vupen.com/english/advisories/2008/2194/references - Vendor Advisory
References () http://www.zerodayinitiative.com/advisories/ZDI-08-047/ - () http://www.zerodayinitiative.com/advisories/ZDI-08-047/ -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/41087 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/41087 -
References () https://www.exploit-db.com/exploits/5332 - () https://www.exploit-db.com/exploits/5332 -

Information

Published : 2008-03-12 17:44

Updated : 2024-11-21 00:44


NVD link : CVE-2008-1309

Mitre link : CVE-2008-1309

CVE.ORG link : CVE-2008-1309


JSON object : View

Products Affected

realnetworks

  • realplayer
CWE
CWE-399

Resource Management Errors