Vulnerabilities > CVE-2008-3064 - Unspecified vulnerability in Realnetworks Realplayer 10.0/10.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN realnetworks
nessus
Summary
Unspecified vulnerability in RealNetworks RealPlayer Enterprise, RealPlayer 10, and RealPlayer 10.5 before build 6.0.12.1675 has unknown impact and attack vectors, probably related to accessing local files, aka a "Local resource reference vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows |
NASL id | REALPLAYER_6_0_14_806.NASL |
description | According to its build number, the installed version of RealPlayer / on the remote Windows host suffers from possibly several issues : - Heap memory corruption issues in several ActiveX controls can lead to arbitrary code execution. (CVE-2008-1309) - An unspecified local resource reference vulnerability. (CVE-2008-3064) - An SWF file heap-based buffer overflow. (CVE-2007-5400) - A buffer overflow involving the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 33744 |
published | 2008-07-28 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/33744 |
title | RealPlayer for Windows < Build 6.0.14.806 / 6.0.12.1675 Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | CVE-2008-3064 An illegal resource reference vulnerability exists in the ActiveX Control of RealNetworks RealPlayer. For exploiting the vulnerability, the attacker may build a special web page and entrap the victim into visiting it, if the local system has installed RealPlayer, the local resources (or any other illegal resources) will be accessed. This vulnerability may assist in exploitation of other vulnerabilities. RealPlayer 10.6 and previous versions The vendor has fixed this vulnerability, the vendor's advisory is available on: <a href=http://service.real.com/realplayer/security/07252008_player/en/ target=_blank>http://service.real.com/realplayer/security/07252008_player/en/</a> |
id | SSV:3884 |
last seen | 2017-11-19 |
modified | 2008-08-20 |
published | 2008-08-20 |
reporter | Root |
title | RealNetworks RealPlayer ActiveX Illegal Resource Reference Vulnerability |
Statements
contributor | Joshua Bressers |
lastmodified | 2008-07-31 |
organization | Red Hat |
statement | According to RealNetworks this flaw does not affect the Linux version of RealPlayer. |
References
- http://service.real.com/realplayer/security/07252008_player/en/
- http://service.real.com/realplayer/security/07252008_player/en/
- http://www.securityfocus.com/archive/1/494934/100/0/threaded
- http://www.securityfocus.com/archive/1/494934/100/0/threaded
- http://www.securityfocus.com/bid/30378
- http://www.securityfocus.com/bid/30378
- http://www.securitytracker.com/id?1020564
- http://www.securitytracker.com/id?1020564
- http://www.vupen.com/english/advisories/2008/2194/references
- http://www.vupen.com/english/advisories/2008/2194/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44014
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44014