Realnetworks · Realplayer Enterprise · CVE-2010-4392
**Name of the Vulnerable Software and Affected Versions**
RealPlayer versions 11.0 through 11.1
RealPlayer SP versions 1.0 through 1.1.5
RealPlayer Enterprise versions 2.1.2 and 2.1.3
Linux RealPlayer version 11.0.2.1744
HelixPlayer version 1.0.6
**Description**
The issue is related to a heap-based buffer overflow that allows remote attackers to execute arbitrary code via crafted ImageMap data in a RealMedia file. This is due to certain improper integer calculations.
**Recommendations**
For RealPlayer versions 11.0 through 11.1, update to a version that fixes the improper integer calculations issue.
For RealPlayer SP versions 1.0 through 1.1.5, update to a version that fixes the improper integer calculations issue.
For RealPlayer Enterprise versions 2.1.2 and 2.1.3, update to a version that fixes the improper integer calculations issue.
For Linux RealPlayer version 11.0.2.1744, update to a version that fixes the improper integer calculations issue.
For HelixPlayer version 1.0.6, update to a version that fixes the improper integer calculations issue.