FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0611

This CVE name corresponds to:

Entered Topic
2005-03-04 realplayer -- remote heap overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0611
Phase Assigned(20050302)

Description

Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.

References

Source Reference
BUGTRAQ 20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability
VULNWATCH 20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability
CONFIRM http://service.real.com/help/faq/security/050224_player/EN/
REDHAT RHSA-2005:265
REDHAT RHSA-2005:271
OVAL oval:org.mitre.oval:def:11419