Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-2922
Mitre link : CVE-2005-2922
CVE.ORG link : CVE-2005-2922
JSON object : View
Products Affected
realnetworks
- realone_player
- realplayer
- rhapsody
- helix_player
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer