Rapid7 Vulnerability & Exploit Database

RealPlayer ActiveX Control 'Console' Property Memory Corruption

Back to Search

RealPlayer ActiveX Control 'Console' Property Memory Corruption

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
03/11/2008
Created
07/25/2018
Added
05/16/2008
Modified
02/13/2015

Description

RealPlayer versions up to 11.0.1 (build 6.0.14.794) have a vulnerability in the rmoc3260.dll ActiveX control which can lead to remote code execution.

The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll 6.0.10.45 in RealNetworks RealPlayer 11.0.1 build 6.0.14.794 does not properly manage memory for the Console property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory. NOTE: some of these details are obtained from third party information.

Solution(s)

  • realplayer-upgrade-11_0_2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;