First published: Fri Oct 04 2002(Updated: )
Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealNetworks RealJukebox 2 | =1.0.2.340 | |
RealNetworks RealJukebox 2 | =1.0.2.379 | |
RealNetworks RealJukebox 2 Plus | =1.0.2.340 | |
RealNetworks RealJukebox 2 Plus | =1.0.2.379 | |
RealNetworks RealPlayer | =6.0.10.505-gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1014 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2002-1014, users should update RealJukebox or RealOne Player to the latest version that addresses this vulnerability.
CVE-2002-1014 affects RealJukebox versions 1.0.2.340 and 1.0.2.379, as well as RealOne Player Gold version 6.0.10.505.
CVE-2002-1014 facilitates remote code execution attacks via a buffer overflow when processing malicious RFS skin files.
If you do not use the affected versions of RealJukebox or RealOne Player, your system is not directly impacted by CVE-2002-1014.