Vulnerability Details CVE-2003-0141
The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.4%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2003-0141
-
cpe:2.3:a:realnetworks:realone_enterprise_desktop:6.0.11.774
-
cpe:2.3:a:realnetworks:realone_player:2.0
-
cpe:2.3:a:realnetworks:realone_player:6.0.10.505
-
cpe:2.3:a:realnetworks:realone_player:6.0.11.818
-
cpe:2.3:a:realnetworks:realone_player:6.0.11.830
-
cpe:2.3:a:realnetworks:realone_player:6.0.11.841
-
cpe:2.3:a:realnetworks:realone_player:6.0.11.853
-
cpe:2.3:a:realnetworks:realone_player:9.0.0.288
-
cpe:2.3:a:realnetworks:realone_player:9.0.0.297
-
cpe:2.3:a:realnetworks:realplayer:8.0