Immune Systems:
* RealPlayer 14.0.0
* RealPlayer Enterprise 2.1.4
* Mac RealPlayer 12.0.0.1548
* Linux RealPlayer 11.0.2.2315
The vulnerability is caused by a heap overflow error when handling malformed RA5 files, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Disclosure Timeline:
2010-02-25 - Vendor notified
2010-12-05 - Status update received
2010-12-10 - Coordinated disclosure