CVE-2006-0323: Buffer Overflow
Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0323?
CVE-2006-0323 is categorized as a critical severity vulnerability due to potential remote code execution.
How do I fix CVE-2006-0323?
To fix CVE-2006-0323, update affected products such as RealPlayer and Helix Player to the latest versions with security patches.
Which products are affected by CVE-2006-0323?
CVE-2006-0323 affects multiple RealNetworks products including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player.
What type of attack is associated with CVE-2006-0323?
CVE-2006-0323 is exploited via a crafted SWF file that triggers a buffer overflow, allowing execution of arbitrary code.
Can CVE-2006-0323 be exploited remotely?
Yes, CVE-2006-0323 can be exploited remotely through a malicious Flash file sent to a vulnerable system.