CVE-2005-2922

UnknownEPSS 5.78%

Last modified

CVE-2005-2922 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.. EPSS estimates a 5.78% chance of exploitation in the next 30 days.

Description

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

Metrics

EPSS Probability
5.78%

92.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RealnetworksHelix Player10.0
RealnetworksHelix Player10.0.1
RealnetworksHelix Player10.0.2
RealnetworksHelix Player10.0.3
RealnetworksHelix Player10.0.4
RealnetworksHelix Player10.0.5
RealnetworksHelix Player10.0.6
RealnetworksRealone PlayerAll versions
RealnetworksRealone Player0.288
RealnetworksRealone Player0.297
RealnetworksRealone Player1.0
RealnetworksRealone Player2.0
RealnetworksRealplayerAll versions
RealnetworksRealplayer8.0
RealnetworksRealplayer10.0
RealnetworksRealplayer10.0.0.305
RealnetworksRealplayer10.0.0.331
RealnetworksRealplayer10.0.1
RealnetworksRealplayer10.0.2
RealnetworksRealplayer10.0.3
RealnetworksRealplayer10.0.4
RealnetworksRealplayer10.0.5
RealnetworksRealplayer10.0.6
RealnetworksRealplayer10.5
RealnetworksRealplayer10.5_6.0.12.1040
RealnetworksRealplayer10.5_6.0.12.1053
RealnetworksRealplayer10.5_6.0.12.1056
RealnetworksRealplayer10.5_6.0.12.1059
RealnetworksRealplayer10.5_6.0.12.1069
RealnetworksRealplayer10.5_6.0.12.1235
RealnetworksRhapsody3.0
RealnetworksRhapsody3.0_build_0.815

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-2922?
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.
How severe is CVE-2005-2922?
Severity scoring for CVE-2005-2922 is pending analysis. The EPSS model estimates a 5.78% probability of exploitation in the next 30 days.
How do I fix CVE-2005-2922?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-2922?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST