|
RealPlayer是一款可自由下载的rm格式的播放器,是由realnetworks公司开发的。日前在real产品上发现一个缓冲溢出漏洞。当受影响产品用来播放过长文件名的文件,并且执行“播放”菜单中两个指定操作中的任何一个时,会发生缓冲溢出。这会导致藏在文件名内的任意代码被执行。
攻击方法:
暂无
受影响软件:
real networks realone player
real networks realone player 2.0
real networks realplayer g2
real networks realplayer 6.0 win32
real networks realplayer 7.0 win32
real networks realplayer 8.0 win32
real networks realplayer 8.0 win32
解决方案:
real networks公司已发布了升级补丁,可解决此安全问题。
real networks realplayer g2:
real networks realone player :
real networks patch skinpatchr11s.rmp
http://service.real.com/help/faq/security/07092002/skinpatchr11s.rmp
real networks realone player 2.0:
real networks patch skinpatchr11s.rmp
http://service.real.com/help/faq/security/07092002/skinpatchr11s.rmp
real networks realplayer 6.0 win32:
real networks realplayer 7.0 win32:
real networks realplayer 8.0 win32:
|