CVE-2009-4246
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD
Description
Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows user-assisted remote attackers to execute arbitrary code via a malformed .RJS skin file that contains a web.xmb file with crafted length values.
Affected (18)
Products: Realnetworks: Realplayer, Realplayer Enterprise, Realplayer Sp, Helix Player
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.5 | |
| All versions | |
| Version 1.0.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
| Running on/with | Platform Versions |
|---|---|
Apple Mac Os X | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 | |
| Version 10.0 |
References (16)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.