The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Realone_enterprise_desktop | Realnetworks | 6.0.11.774 (including) | 6.0.11.774 (including) |
Realone_player | Realnetworks | 2.0 (including) | 2.0 (including) |
Realone_player | Realnetworks | 6.0.10.505-gold (including) | 6.0.10.505-gold (including) |
Realone_player | Realnetworks | 6.0.11.818 (including) | 6.0.11.818 (including) |
Realone_player | Realnetworks | 6.0.11.830 (including) | 6.0.11.830 (including) |
Realone_player | Realnetworks | 6.0.11.841 (including) | 6.0.11.841 (including) |
Realone_player | Realnetworks | 6.0.11.853 (including) | 6.0.11.853 (including) |
Realone_player | Realnetworks | 9.0.0.288 (including) | 9.0.0.288 (including) |
Realone_player | Realnetworks | 9.0.0.297 (including) | 9.0.0.297 (including) |
Realplayer | Realnetworks | 8.0 (including) | 8.0 (including) |