PT-2010-5042 · Realnetworks · Realplayer Sp+1

Publicado

2010-10-15

·

Atualizado

2010-10-19

·

CVE-2010-3751

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealPlayer versions 11.0 through 11.1 RealPlayer SP versions 1.0 through 1.1.4
Description The issue is related to multiple heap-based buffer overflows in an ActiveX control. Remote attackers can execute arbitrary code via a long .smil argument to the tfile, pnmm, or cdda protocol handlers.
Recommendations For RealPlayer versions 11.0 through 11.1, update to a version that is not affected by this issue. For RealPlayer SP versions 1.0 through 1.1.4, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the tfile, pnmm, and cdda protocol handlers until a patch is available.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3751
ZDI-10-213

Produtos afetados

Realplayer
Realplayer Sp