PT-2010-5042 · Realnetworks · Realplayer Sp+1

Published

2010-10-15

·

Updated

2010-10-19

·

CVE-2010-3751

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealPlayer versions 11.0 through 11.1 RealPlayer SP versions 1.0 through 1.1.4
Description The issue is related to multiple heap-based buffer overflows in an ActiveX control. Remote attackers can execute arbitrary code via a long .smil argument to the tfile, pnmm, or cdda protocol handlers.
Recommendations For RealPlayer versions 11.0 through 11.1, update to a version that is not affected by this issue. For RealPlayer SP versions 1.0 through 1.1.4, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the tfile, pnmm, and cdda protocol handlers until a patch is available.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3751
ZDI-10-213

Affected Products

Realplayer
Realplayer Sp