HIGH · 9.3

CVE-2005-2922

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a ...

Vulnerability Description

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
RealnetworksHelix Player10.0
RealnetworksRealone PlayerAll versions
RealnetworksRealplayerAll versions
RealnetworksRhapsody3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2005-2922?

CVE-2005-2922 is a vulnerability with a CVSS score of 9.3 (HIGH). Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a ...

How severe is CVE-2005-2922?

CVE-2005-2922 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2922?

Check the references section above for vendor advisories and patch information. Affected products include: Realnetworks Helix Player, Realnetworks Realone Player, Realnetworks Realplayer, Realnetworks Rhapsody.