Skip to main content

RealPlayer AVI Header Parsing Buffer Overflow Vulnerability

Last Update Date: 31 Jan 2011 16:43 Release Date: 31 Jan 2011 6338 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the "vidplin.dll" module when processing malformed header data, which could be exploited by attackers to compromise a vulnerable system by convincing a user to open a malicious media file or visit a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • RealPlayer versions 11.0 through 11.1
  • RealPlayer SP versions 1.0 through 1.1.5
  • RealPlayer versions 14.0.0 through 14.0.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to RealPlayer version 14.0.2.

Vulnerability Identifier


Source


Related Link