CVE-2005-2922: Buffer Overflow
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2922?
CVE-2005-2922 is considered a high severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2005-2922?
To fix CVE-2005-2922, users should update to the latest version of RealNetworks products or apply any available patches from RealNetworks.
Which products are affected by CVE-2005-2922?
CVE-2005-2922 affects RealPlayer 10.x, RealOne Player, and Helix Player across multiple versions.
What types of attacks can exploit CVE-2005-2922?
CVE-2005-2922 can be exploited through crafted HTTP requests that use chunked Transfer-Encoding, leading to buffer overflow vulnerabilities.
Is CVE-2005-2922 still a concern for users of RealNetworks products?
Yes, CVE-2005-2922 remains a concern for users of outdated versions of affected RealNetworks products.