Skip to main content

RealPlayer RealVideo Renderer Plugin Remote Heap Overflow Vulnerability

Last Update Date: 23 Mar 2011 09:45 Release Date: 23 Mar 2011 5519 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a heap overflow error in the RealVideo Renderer plugin for RealMedia (rvrender.dll) when processing a malformed IVR (Internet Video Recording) file, which could be exploited by attackers to execute arbitrary code by convincing a user to open a malicious media file or visit a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • RealPlayer version 14.0.2.633 and prior

Solutions

  • It is not aware of any vendor-supplied patch.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link