CVE-2005-3677: Buffer Overflow
Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3677?
CVE-2005-3677 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2005-3677?
To mitigate CVE-2005-3677, it is recommended to upgrade RealPlayer to a secure version that is not vulnerable to this exploit.
Which versions of RealPlayer are affected by CVE-2005-3677?
CVE-2005-3677 affects RealPlayer versions 10.0 and 10.5, including specific builds of 10.5.
What kind of attacks can be executed using CVE-2005-3677?
CVE-2005-3677 allows attackers to execute arbitrary code by exploiting a buffer overflow through crafted image files in RealPlayer Skin files.
Is there a workaround for CVE-2005-3677?
There are no effective workarounds for CVE-2005-3677; the best course of action is to apply the necessary updates.