Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 27th, 2004, 09:53 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default RealPlayer/RealOne "DUNZIP32.dll" Buffer Overflow Vulnerability

Highly critical

Secunia

Quote:
The vulnerability is caused due to a boundary error in a 3rd-party compression library (DUNZIP32.dll) when processing skin files. This can be exploited to cause a buffer overflow via a specially crafted skin file
  #2  
Old November 5th, 2004, 02:44 AM
still_longhorn's Avatar
still_longhorn still_longhorn is offline
Frequent Poster
 
Join Date: Oct 2004
Posts: 256
Default Re: RealPlayer/RealOne "DUNZIP32.dll" Buffer Overflow Vulnerability

A buffer overflow condition exists due to insufficient bounds checking of fields in skinfiles. There is an unchecked buffer for the "CONTROLnImage" field of the "skin.ini" file. By supplying an overly long filename as a value for this field, it is possible to overwrite stack variables. An attacker may exploit this condition to overwrite the return address with a pointer to embedded attacker-supplied instructions.
To exploit this issue the attacker must transmit the maliciously constructed skinfile to a victim of the attack. This may be done via a webpage or HTML e-mail. Exploitation of this issue may result in execution of attacker-supplied instructions with the privileges of the user opening the malicious skinfile.

A proof-of-concept has been provided. The following must be saved in a zipfile and the extension must be changed to .rjs:
[MAIN]
SkinFamilyCount=5
CONTROL1Image=aaaaaaaaaa... long'a'
If this example is loaded with a web browser, the Real application will be called and will crash.
Exploit code has been released by UNYUN <unyun@shadowpenguin.org>:
realjukebox2_exploit.c

Fixes are available:
Real Networks RealOne Player Gold for Windows 6.0.10 .505:
Real Networks Patch skinpatchr11s.rmp
http://www.service.real.com/help/faq...npatchr11s.rmp
__________________
Defeat is worse than death. You have to live with defeat....

One does not argue with a hypothesis. He tests it!
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:30 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums