CVE-2012-0923

RealNetworks RealPlayer <15.02.71 - RCE

Title source: llm
STIX 2.1

Description

The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to execute arbitrary code via a crafted RV20 RealVideo video stream.

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47896
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/78912
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51884

Scores

EPSS 0.0277
EPSS Percentile 86.2%

Details

CWE
CWE-94
Status published
Products (33)
realnetworks/realplayer 14.0.0
realnetworks/realplayer 14.0.1
realnetworks/realplayer 14.0.1.609
realnetworks/realplayer 14.0.1.633
realnetworks/realplayer 14.0.2
realnetworks/realplayer 14.0.3
realnetworks/realplayer 14.0.4
realnetworks/realplayer 14.0.5
realnetworks/realplayer 14.0.6
realnetworks/realplayer 14.0.7
... and 23 more
Published Feb 08, 2012
Tracked Since Feb 18, 2026