First published: Sat Mar 29 2003(Updated: )
The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealNetworks RealPlayer | =6.0.11.841 | |
RealNetworks RealPlayer | =9.0.0.297 | |
RealNetworks RealPlayer | =2.0 | |
RealNetworks RealOne Enterprise Desktop | =6.0.11.774 | |
RealNetworks RealPlayer | =9.0.0.288 | |
RealNetworks RealPlayer | =6.0.11.830 | |
RealPlayer | =8.0 | |
RealNetworks RealPlayer | =6.0.10.505-gold | |
RealNetworks RealPlayer | =6.0.11.818 | |
RealNetworks RealPlayer | =6.0.11.853 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0141 is considered a high severity vulnerability due to its potential to allow remote attackers to overwrite arbitrary memory.
To remediate CVE-2003-0141, users should upgrade to a patched version of RealOne Player or RealPlayer that addresses this vulnerability.
CVE-2003-0141 affects RealOne Player versions 6.0.11.x and earlier, RealPlayer 8, and several other specific versions of RealNetworks software.
CVE-2003-0141 can enable remote attackers to exploit the vulnerability via a specially crafted PNG graphic, potentially leading to arbitrary code execution.
While the most effective solution is to upgrade, temporarily avoiding opening untrusted PNG files can reduce exposure to CVE-2003-0141.