Skip to main content

RealNetworks RealPlayer SWF Frame Handling Buffer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 28 Jul 2008 4848 Views

RISK: Medium Risk

A vulnerability has been identified in RealPlayer, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a design error within the handling of frames in Shockwave Flash (SWF) files and can be exploited to cause a heap-based buffer overflow.

Successful exploitation may allow execution of arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • RealPlayer 10.x
  • RealPlayer 11.x
  • RealPlayer Enterprise 1.x


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to the latest version:
http://service.real.com/realplayer/security/07252008_player/en/


Vulnerability Identifier


Source


Related Link