RealPlayer for Windows < 17.0.4.61 RMP Buffer Overflow

This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.


Synopsis :

A multimedia application on the remote Windows host is affected by a
buffer overflow vulnerability.

Description :

According to its build number, the installed version of RealPlayer on
the remote Windows host is earlier than 17.0.4.61. It is, therefore,
affected by a buffer overflow vulnerability when handling the
'encoding', 'trackid', and 'version' attributes in RealPlayer Metadata
Package (RMP) files that could lead to arbitrary code execution.

See also :

http://seclists.org/fulldisclosure/2013/Dec/150
http://service.real.com/realplayer/security/12202013_player/en/

Solution :

Upgrade to RealPlayer Cloud 17.0.4.61 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 71772 ()

Bugtraq ID: 64398
64695

CVE ID: CVE-2013-6877
CVE-2013-7260

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now