Title: RealPlayer Multiple Products Audio Stream Multi-rate Data Remote Overflow
Info
Disclosure
Dec 10, 2010
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Dec 10, 2010
Description
RealPlayer is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted multi-rate audio stream, a context-dependent attacker can potentially execute arbitrary code.
Upgrade RealPlayer to version 14.0.0 or SP 1.0 or higher for Windows, 12.0.0.1444 or higher for Mac, or 11.0.2.2315 or higher for Linux, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.