CVE-2000-0280: Buffer Overflow

Published Apr 3, 2000
·
Updated

Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.

Affected Software

2 affected components
RealNetworks RealPlayer=6.0
RealNetworks RealPlayer=7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove RealPlayer from your environment.

    Uninstall RealPlayer from affected systems or remove the RealPlayer client until an official vendor patch/fix is available.

  2. Compensating control

    At the network perimeter, block or filter media streams and HTTP responses that contain unusually long Location URLs and restrict access to streaming services to trusted sources to reduce exposure to remote Location-URL attacks.

  3. Operational

    Advise users not to open untrusted media or follow unfamiliar Location URLs; monitor systems for RealPlayer crashes or denial-of-service behaviour and isolate/restart affected hosts while remediation is applied.

Event History

Apr 3, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Apr 26, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0280?

CVE-2000-0280 has a high severity rating due to its potential to cause remote denial of service attacks.

2

How do I fix CVE-2000-0280?

To fix CVE-2000-0280, upgrade to a later version of RealPlayer that is not vulnerable to this buffer overflow.

3

What versions of RealPlayer are affected by CVE-2000-0280?

CVE-2000-0280 affects RealPlayer versions 6.0 and 7.0 on Windows.

4

Can CVE-2000-0280 be exploited remotely?

Yes, CVE-2000-0280 can be exploited remotely by attackers through a specially crafted long Location URL.

5

What impact does CVE-2000-0280 have on system security?

The impact of CVE-2000-0280 on system security includes potential crashes and denial of service for users of the affected RealPlayer versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203