CVE-2008-1309
N/A
N/A
Summary
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41087
- http://www.vupen.com/english/advisories/2008/2194/references
- http://service.real.com/realplayer/security/07252008_player/en/
- http://secunia.com/advisories/29315
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html
- http://www.securitytracker.com/id?1019576
- https://www.exploit-db.com/exploits/5332
- http://www.vupen.com/english/advisories/2008/0842
- http://www.zerodayinitiative.com/advisories/ZDI-08-047/
- http://www.kb.cert.org/vuls/id/831457
- http://www.securityfocus.com/archive/1/494779/100/0/threaded
- http://www.securitytracker.com/id?1020563
- http://www.securityfocus.com/bid/28157
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41087
- http://www.vupen.com/english/advisories/2008/2194/references
- http://service.real.com/realplayer/security/07252008_player/en/
- http://secunia.com/advisories/29315
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html
- http://www.securitytracker.com/id?1019576
- https://www.exploit-db.com/exploits/5332
- http://www.vupen.com/english/advisories/2008/0842
- http://www.zerodayinitiative.com/advisories/ZDI-08-047/
- http://www.kb.cert.org/vuls/id/831457
- http://www.securityfocus.com/archive/1/494779/100/0/threaded
- http://www.securitytracker.com/id?1020563
- http://www.securityfocus.com/bid/28157
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.