RealPlayer Data Packet Stack Overflow
November 10, 2005
May 28, 2005
High (Remote Code Execution)
RealPlayer 10.5 (220.127.116.110-1235)
RealOne Player v2
RealOne Player v1
RealPlayer 10 (10.0.0 - 5)
Helix Player (10.0.0 - 5)
eEye Digital Security has discovered a critical vulnerability in
RealPlayer. The vulnerability allows a remote attacker to reliably
overwrite stack memory with arbitrary data and execute arbitrary code in
the context of the user who executed the player.
This specific flaw exists in the first data packet contained in a Real
Media file. By specially crafting a malformed .rm movie file, a direct
stack overwrite is triggered, and reliable code execution is then
The vulnerability is triggered by setting the application specific
length field of the [data packet + 1] to 0x80 - 0xFF this will cause a
The value is sign-extended and passed as the length to memcpy.
Retina Network Security Scanner has been updated to identify this
Blink End Point Protection proactively protects against this
RealNetworks has released a patch for this vulnerability. The patch is
available via the "Check for Update" menu item under Tools on the
RealPlayer menu bar or from
This advisory has been assigned the following ID numbers;
OSVDB ID: 18822
CVE ID: CAN-2005-2629
Brett Moore, Mark Dowd, Paul Gese @ RealNetworks, Mike Schiffman, AJREZ,
Luke, Derek "TEX" Soeder, Andre Audits, "The Claw", and Dug Song.
Copyright (c) 1998-2005 eEye Digital Security
Permission is hereby granted for the redistribution of this alert
electronically. It is not to be edited in any way without express
consent of eEye. If you wish to reprint the whole or any part of this
alert in any other medium excluding electronic medium, please email
alert@eEye.com for permission.
The information within this paper may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are no warranties, implied or express, with regard to this information.
In no event shall the author be liable for any direct or indirect
damages whatsoever arising out of or in connection with the use or
spread of this information. Any use of this information is at the user's