First published: Mon Jan 25 2010(Updated: )
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger heap memory corruption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =11.0.1 | |
RealNetworks Helix Player Linux | =11.0.1 | |
RealPlayer | =10.0 | |
RealNetworks Helix Player Linux | =11.0.0 | |
RealNetworks Helix Player Linux | =10.0 | |
RealPlayer | =11.0.0 | |
RealPlayer | =10.0 | |
RealPlayer | =10.5 | |
RealPlayer | =11.0 | |
RealPlayer | =11.0.1 | |
RealPlayer | =11.0.2 | |
RealPlayer | =11.0.3 | |
RealPlayer | =11.0.4 | |
RealPlayer | =11.0.5 | |
RealPlayer | ||
RealPlayer | =1.0.0 | |
RealPlayer | =1.0.1 | |
Microsoft Windows Operating System | ||
RealPlayer | =10.1 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4241 is rated as a significant vulnerability due to its potential to allow remote code execution.
To fix CVE-2009-4241, you should update RealPlayer to the latest version that addresses this vulnerability.
CVE-2009-4241 affects various versions of RealPlayer and Helix Player, including RealPlayer 10 and 11 on multiple platforms.
Yes, CVE-2009-4241 can be exploited remotely, allowing attackers to execute arbitrary code.
CVE-2009-4241 allows remote attackers to execute arbitrary code through a heap-based buffer overflow attack.