Skip to main content

RealNetworks RealPlayer Internet Video Recording Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2009 4734 Views

RISK: Medium Risk

Two vulnerabilities have been identified in RealNetworks RealPlayer, which could be exploited by attackers to compromise a vulnerable system.

1. Due to a heap corruption error when processing Internet Video Recording (IVR) files containing a malformed field that determines the length of a structure, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into visiting a malicious web page or opening a specially crafted IVR file.

2. Due to a memory corruption error when processing Internet Video Recording (IVR) files with an overly long filename length value, which could allow attackers to crash an affected application or write a null byte to an arbitrary memory address by tricking a user into visiting a malicious web page or opening a specially crafted IVR file.


Impact

  • Remote Code Execution

System / Technologies affected

  • RealNetworks RealPlayer 11

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link