Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Real Networks RealJukebox/RealOne Player Gold Skinfile Buffer Overflow

A proof-of-concept has been provided. The following must be saved in a zipfile and the extension must be changed to .rjs:

[MAIN]
Application=RealJukebox
Version=2
SkinFamilyCount=5

CONTROL1Image=aaaaaaaaaa... long'a'

If this example is loaded with a web browser, the Real application will be called and will crash.

Exploit code has been released by UNYUN <unyun@shadowpenguin.org>:







 

Privacy Statement
Copyright 2008, SecurityFocus