CVE-2005-2922 (CNNVD-200512-913)
中文标题:
RealNetworks产品多个缓冲区溢出漏洞
英文标题:
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions inc...
漏洞描述
中文描述:
RealNetworks提供各种媒体播放器,支持多种格式。 各种RealNetworks产品中存在多个溢出漏洞,允许攻击者入侵用户系统。 1) 处理SWF文件时的溢出漏洞允许在用户系统上执行任意代码; 2) 处理Web页面时存在堆溢出漏洞,允许在用户系统上执行任意代码; 3) 处理MBC文件时的溢出漏洞允许在用户系统上执行任意代码。 此外,在使用"CreateProcess()" API时的漏洞允许执行任意程序。
英文描述:
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| realnetworks | helix_player | 10.0 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0:*:linux:*:*:*:*:*
|
| realnetworks | helix_player | 10.0.1 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0.1:*:linux:*:*:*:*:*
|
| realnetworks | helix_player | 10.0.2 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0.2:*:linux:*:*:*:*:*
|
| realnetworks | helix_player | 10.0.3 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0.3:*:linux:*:*:*:*:*
|
| realnetworks | helix_player | 10.0.4 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0.4:*:linux:*:*:*:*:*
|
| realnetworks | helix_player | 10.0.5 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0.5:*:linux:*:*:*:*:*
|
| realnetworks | helix_player | 10.0.6 | - | - |
cpe:2.3:a:realnetworks:helix_player:10.0.6:*:linux:*:*:*:*:*
|
| realnetworks | realone_player | * | - | - |
cpe:2.3:a:realnetworks:realone_player:*:*:*:*:*:*:*:*
|
| realnetworks | realone_player | 0.288 | - | - |
cpe:2.3:a:realnetworks:realone_player:0.288:*:mac_os_x:*:*:*:*:*
|
| realnetworks | realone_player | 0.297 | - | - |
cpe:2.3:a:realnetworks:realone_player:0.297:*:mac_os_x:*:*:*:*:*
|
| realnetworks | realone_player | 1.0 | - | - |
cpe:2.3:a:realnetworks:realone_player:1.0:*:*:*:*:*:*:*
|
| realnetworks | realone_player | 2.0 | - | - |
cpe:2.3:a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*
|
| realnetworks | realplayer | * | - | - |
cpe:2.3:a:realnetworks:realplayer:*:*:enterprise:*:*:*:*:*
|
| realnetworks | realplayer | 8.0 | - | - |
cpe:2.3:a:realnetworks:realplayer:8.0:*:win32:*:*:*:*:*
|
| realnetworks | realplayer | 10.0 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.0.305 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.0.305:*:mac_os:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.0.331 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.0.331:*:mac_os:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.1 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.1:*:linux:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.2 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.2:*:linux:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.3 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.3:*:linux:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.4 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.4:*:linux:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.5 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.5:*:linux:*:*:*:*:*
|
| realnetworks | realplayer | 10.0.6 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.0.6:*:linux:*:*:*:*:*
|
| realnetworks | realplayer | 10.5 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.5_6.0.12.1040 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1040:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.5_6.0.12.1053 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1053:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.5_6.0.12.1056 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1056:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.5_6.0.12.1059 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1059:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.5_6.0.12.1069 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1069:*:*:*:*:*:*:*
|
| realnetworks | realplayer | 10.5_6.0.12.1235 | - | - |
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1235:*:*:*:*:*:*:*
|
| realnetworks | rhapsody | 3.0 | - | - |
cpe:2.3:a:realnetworks:rhapsody:3.0:*:*:*:*:*:*:*
|
| realnetworks | rhapsody | 3.0_build_0.815 | - | - |
cpe:2.3:a:realnetworks:rhapsody:3.0_build_0.815:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:N/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2005-2922 |
2025-11-11 15:17:36 | 2025-11-11 07:32:28 |
| NVD | nvd_CVE-2005-2922 |
2025-11-11 14:51:21 | 2025-11-11 07:41:14 |
| CNNVD | cnnvd_CNNVD-200512-913 |
2025-11-11 15:08:49 | 2025-11-11 07:49:03 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200512-913
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 32
- data_sources: ['cve'] -> ['cve', 'nvd']