[Full-disclosure] Real Networks RealPlayer ActiveX Heap Use After Free Vulnerability
elazar at hushmail.com
Fri Jul 25 21:07:44 BST 2008
-----BEGIN PGP SIGNED MESSAGE-----
RealPlayer 11 (11.0.0 - 11.0.2 builds 126.96.36.1998 - 188.8.131.522)
RealPlayer 10.5 (184.108.40.2060-220.127.116.113, 18.104.22.1688, 22.214.171.1241)
The WindowName and Controls properties of rmoc3260.dll do not
manage heap memory properly resulting in a use after free condition
which can overwrite heap management structures resulting in code
execution. Note that this is the same issue that affected the
Console property(which was fixed in Real Player 11.0.2/rmoc3260.dll
version 126.96.36.199, however these were not).
Real Networks has released fixes for this issue, please see
-----BEGIN PGP SIGNATURE-----
Version: Hush 3.0
Note: This signature can be verified at https://www.hushtools.com/verify
-----END PGP SIGNATURE-----
Click here for great computer networking solutions!
Full-Disclosure is hosted and sponsored by Secunia.