CVE-2010-0416: Buffer Overflow

Published Feb 4, 2010
·
Updated

A possible buffer overflow flaw was found in the RealPlayer's / HelixPlayer's function performing URL unescaping (HTTP %-escapes unescaping, e.g. %20 -> space):

http://lists.helixcommunity.org/pipermail/common-cvs/2007-July/014956.html https://helixcommunity.org/viewcvs/common/util/hxurl.cpp?view=log#rev1.24.4.1.4.1

Function always assumed % character was always followed by at least two extra hex characters. If no or only one character followed, unescaping function failed to properly detect the end of the URL string (test is done by comparing character on the current position with '\0') and continued processing content of the memory after the end of URL buffer until first '\0' was found. Depending on the content of that memory area, this could lead to buffer over-read or over-write.

Same function exists in player/hxclientkit/src/CHXClientSink.cpp too.

Other sources

Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.

MITRE

Affected Software

2 affected components
RealNetworks Helix Player=1.0.6
RealNetworks RealPlayer

Event History

Feb 4, 2010
Data Sourced
via Red Hat·02:38 PM
DescriptionSeverityAffected Software
Feb 18, 2010
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:30 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-0416?

CVE-2010-0416 has been classified as a moderate severity vulnerability.

2

How do I fix CVE-2010-0416?

To fix CVE-2010-0416, update to the latest version of RealPlayer or Helix Player that addresses this vulnerability.

3

What software is affected by CVE-2010-0416?

CVE-2010-0416 affects RealPlayer and Helix Player on Linux, specifically version 1.0.6 of Helix Player.

4

What type of vulnerability is CVE-2010-0416?

CVE-2010-0416 is a buffer overflow vulnerability related to URL unescaping functionality.

5

Can CVE-2010-0416 be exploited remotely?

Yes, CVE-2010-0416 can potentially be exploited remotely through crafted URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203