[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CALo60KmU=0pJ2oJ7Xr+9Gk=sHHWvqaGerKbXvLjT=c2QToFCcQ@mail.gmail.com>
Date: Tue, 30 Oct 2012 10:43:25 -0400
From: Antony widmal <antony.widmal@...il.com>
To: kaveh ghaemmaghami <kavehghaemmaghami@...glemail.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: RealPlayer 15.0.6.14(.3g2) WriteAV
	Vulnerability
You can be mistaken for a troller, that's for sure, but I know you're just
very stupid.
On Tue, Oct 30, 2012 at 5:37 AM, kaveh ghaemmaghami <
kavehghaemmaghami@...glemail.com> wrote:
> Hello List
> i want to warn u about RealPlayer 15.0.6.14 memory corruption during
> the handling of the 3g2 files
>
> look what awesome coolkaveh found
> Lets kill that bug
> Be safe
>
> <<<<keep it priv8 >>>
>
>
> Title    :  RealPlayer 15.0.6.14(.3g2) WriteAV Vulnerability
> Version  :  15.0.6.14
> Date     :  2012-10-29
> Vendor   :  http://www.real.com/
> crash    :  http://img543.imageshack.us/img543/9130/pocm.jpg
> Impact   :  High
> Contact  :  coolkaveh [at] rocketmail.com
> Twitter  :  @coolkaveh
> tested   :  windows 7 x64
> Author   :  coolkaveh
>
> ###############################################################################
> Bug :
> ----
> Memory corruption during the handling of the 3g2 files context-dependent
> Successful exploits can allow attackers to execute arbitrary code
> ----
>
> ################################################################################
> (f84.8c8): Access violation - code c0000005 (first chance)
> First chance exceptions are reported before any exception handling.
> This exception may be expected and handled.
> eax=040d1370
> ebx=7fdfe2d0
> ecx=0a67f798
> edx=0a67f7a8
> esi=00000000
> edi=00000004
> eip=66fc94df
> esp=3c6c1a80
> ebp=0a67f764 iopl=0         nv up ei pl nz na po nc
> cs=0023  ss=002b  ds=002b  es=002b  fs=0053  gs=002b
> efl=00010202
> *** ERROR: Symbol file could not be found.  Defaulted to export
> symbols for C:\Program Files (x86)\Real\RealPlayer\codecs\dmp4.dll -
> dmp4!GetGUID+0x1836f:
> 66fc94df 8944241c        mov     dword ptr [esp+1Ch],eax
> ss:002b:3c6c1a9c=????????
> 0:029> !exploitable -v
> HostMachine\HostUser
> Executing Processor Architecture is x86
> Debuggee is in User Mode
> Debuggee is a live user mode debugging session on the local machine
> Event Type: Exception
> Exception Faulting Address: 0x3c6c1a9c
> First Chance Exception Type: STATUS_ACCESS_VIOLATION (0xC0000005)
> Exception Sub-Type: Write Access Violation
>
> Exception Hash (Major/Minor): 0x247c7f22.0x247c7f63
>
> Stack Trace:
> dmp4!GetGUID+0x1836f
> Instruction Address: 0x0000000066fc94df
>
> Description: User Mode Write AV
> Short Description: WriteAV
> Exploitability Classification: EXPLOITABLE
> Recommended Bug Title: Exploitable - User Mode Write AV starting at
> dmp4!GetGUID+0x000000000001836f (Hash=0x247c7f22.0x247c7f63)
>
> User mode write access violations that are not near NULL are exploitable.
>
> ################################################################################
> Proof of concept included.
> http://www21.zippyshare.com/v/83302158/file.html
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists
 
