PT-2013-6303 · Realnetworks · Realplayer

Gabor Seljan

·

Published

2013-12-19

·

Updated

2020-05-11

·

CVE-2013-7260

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RealPlayer versions prior to 17.0.4.61 on Windows RealPlayer versions prior to 12.0.1.1738 on Mac
Description The issue allows remote attackers to execute arbitrary code via a long version number or encoding declaration in the XML declaration of an RMP file. This is due to multiple stack-based buffer overflows.
Recommendations For RealPlayer versions prior to 17.0.4.61 on Windows, update to version 17.0.4.61 or later. For RealPlayer versions prior to 12.0.1.1738 on Mac, update to version 12.0.1.1738 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7260

Affected Products

Realplayer