mailing list archives
Real Networks RealPlayer ActiveX Heap Use After Free Vulnerability
From: "Elazar Broad" <elazar () hushmail com>
Date: Fri, 25 Jul 2008 16:07:44 -0400
-----BEGIN PGP SIGNED MESSAGE-----
RealPlayer 11 (11.0.0 - 11.0.2 builds 126.96.36.1998 - 188.8.131.522)
RealPlayer 10.5 (184.108.40.2060-220.127.116.113, 18.104.22.1688, 22.214.171.1241)
The WindowName and Controls properties of rmoc3260.dll do not
manage heap memory properly resulting in a use after free condition
which can overwrite heap management structures resulting in code
execution. Note that this is the same issue that affected the
Console property(which was fixed in Real Player 11.0.2/rmoc3260.dll
version 126.96.36.199, however these were not).
Real Networks has released fixes for this issue, please see
-----BEGIN PGP SIGNATURE-----
Version: Hush 3.0
Note: This signature can be verified at https://www.hushtools.com/verify
-----END PGP SIGNATURE-----
Click here for great computer networking solutions!
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- Real Networks RealPlayer ActiveX Heap Use After Free Vulnerability Elazar Broad (Jul 25)