CVE-2014-3113
RealPlayer < 17.0.10.8 - Remote Code Execution via MP4 Atom Parsing
Title source: llmDescription
Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_misc
http://www.fortiguard.com/advisory/RealNetworks-RealPlayer-Memory-Corruption/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1030524
Vendor Advisory x_refsource_confirm
http://service.real.com/realplayer/security/06272014_player/en/
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59238
Scores
EPSS
0.1220
EPSS Percentile
93.9%
Details
CWE
CWE-119
Status
published
Products (2)
realnetworks/realplayer
17.0.4.60
realnetworks/realplayer
< 17.0.8.22
Published
Jul 07, 2014
Tracked Since
Feb 18, 2026