The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to execute arbitrary code via a crafted RV20 RealVideo video stream.
Vulnerable Systems:
* Windows RealPlayer 15.0.1.13 and prior.
Immune Systems:
* RealPlayer 15.02.71
Real Networks RealPlayer is prone to a remote code-execution vulnerability. Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected application. Failed attacks may cause denial-of-service conditions.
Vendor Status:
RealNetworks is making available product upgrades that contain security bug fixes