CVE-2010-2998

RealNetworks RealPlayer <11.1 - RCE

Title source: llm
STIX 2.1

Description

Array index error in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.0.1 allows remote attackers to execute arbitrary code via malformed sample data in a RealMedia .IVR file, related to a "malformed IVR pointer index" issue.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44144
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-209/

Scores

EPSS 0.0163
EPSS Percentile 82.1%

Details

CWE
CWE-20
Status published
Products (9)
realnetworks/realplayer 11.0
realnetworks/realplayer 11.0.1
realnetworks/realplayer 11.0.2
realnetworks/realplayer 11.0.3
realnetworks/realplayer 11.0.4
realnetworks/realplayer 11.0.5
realnetworks/realplayer 11.1
realnetworks/realplayer_sp 1.0.0
realnetworks/realplayer_sp 1.0.1
Published Oct 19, 2010
Tracked Since Feb 18, 2026