[VIM] RealPlayer Updates of October 25, 2007

George A. Theall theall at tenablesecurity.com
Tue Oct 30 01:24:34 UTC 2007


Real released an advisory on October 25, 2007 about several overflows in 
RealPlayer and gives credit to Piotr Bania and several others.

Also last week Piotr released two advisories covering issues in 
RealPlayer that could be triggered with a specially-crafted .mov file to 
execute code remotely:

   http://www.piotrbania.com/all/adv/realplayer-heap-corruption-adv.txt
   http://www.piotrbania.com/all/adv/realplayer-memory-corruption-adv.txt

Oddly, Real's advisory doesn't mention anything about .mov files per se. 
And neither of Piotr's advisories offers a solution, although they say 
Real responded to them a year ago. Anyone else notice this? Are the 
issues related or not?

George
-- 
theall at tenablesecurity.com


More information about the VIM mailing list