RealPlayer Contains a vulnerability that can be exploited to corrupt memory via specially crafted spectral data .
Credit:
The information has been provided by Carsten Eiram .
The original article can be found at: http://seclists.org/fulldisclosure/2010/Dec/514
Vulnerable Systems:
* RealPlayer SP 1.1.4
* RealPlayer Enterprise 2.1.2
* Mac RealPlayer 12.0.0.1444
Immune Systems:
* RealPlayer SP 1.1.5
* RealPlayer Enterprise 2.1.3
* Mac RealPlayer 12.0.0.1548
The vulnerability is caused by an error in the parsing of AAC audio content and can be exploited to corrupt memory via specially crafted spectral data.
Successful exploitation may allow execution of arbitrary code.
CVE Information:
CVE-2010-0125
Disclosure Timeline:
01/03/2010 - Vendor notified.
01/03/2010 - Vendor response.
29/11/2010 - Vendor provides status update.
10/12/2010 - Public disclosure.
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by