CVE Database
/

CVE-2005-2922

Back to search

CVE-2005-2922

Published: Mar 23, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

VendorProductVersions

n/a

n/a

affected
n/a

References

19358
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11444
vdb-entry
signature
x_refsource_OVAL
SUSE-SA:2006:018
vendor-advisory
x_refsource_SUSE
ADV-2006-1057
vdb-entry
x_refsource_VUPEN
1015808
vdb-entry
x_refsource_SECTRACK
RHSA-2005:788
vendor-advisory
x_refsource_REDHAT
19365
third-party-advisory
x_refsource_SECUNIA
17202
vdb-entry
x_refsource_BID
VU#172489
third-party-advisory
x_refsource_CERT-VN
RHSA-2005:762
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now