CVE-2010-4391
RealPlayer 11.0-11.1 and RealPlayer SP 1.0-1.1.5 - Remote Code Execution via Crafted RMX Header Field
Title source: llmDescription
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allows remote attackers to execute arbitrary code via a crafted value in an unspecified header field in an RMX file.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1024861
Vendor Advisory x_refsource_confirm
http://service.real.com/realplayer/security/12102010_player/en/
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-281
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/69851
Scores
EPSS
0.2063
EPSS Percentile
95.7%
Details
CWE
CWE-119
Status
published
Products (19)
realnetworks/realplayer
11.0
realnetworks/realplayer
11.0.1
realnetworks/realplayer
11.0.2
realnetworks/realplayer
11.0.3
realnetworks/realplayer
11.0.4
realnetworks/realplayer
11.0.5
realnetworks/realplayer
11.1
realnetworks/realplayer
2.1.2
realnetworks/realplayer
2.1.3
realnetworks/realplayer_sp
1.0.0
... and 9 more
Published
Dec 14, 2010
Tracked Since
Feb 18, 2026