CVE-2009-4242: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4242 to the following vulnerability:
Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via a GIF file with crafted chunk sizes that trigger improper memory allocation.
References: http://service.real.com/realplayer/security/01192010player/en/ http://www.zerodayinitiative.com/advisories/ZDI-10-006/ http://www.securityfocus.com/archive/1/509096/100/0/threaded http://xforce.iss.net/xforce/xfdb/55795
Other sources
Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/gifcodec.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via a GIF file with crafted chunk sizes that trigger improper memory allocation.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4242?
CVE-2009-4242 is classified as a high severity vulnerability due to its exploitation potential leading to remote code execution.
How do I fix CVE-2009-4242?
To fix CVE-2009-4242, you should update RealPlayer and Helix Player to their latest versions where the vulnerability is patched.
Which versions are affected by CVE-2009-4242?
CVE-2009-4242 affects RealPlayer versions 10.0, 10.5, and 11.0 up to 11.0.4, as well as Helix Player versions 10.0 and 11.0.0 through 11.0.1.
What systems are vulnerable to CVE-2009-4242?
CVE-2009-4242 impacts Linux versions of RealPlayer and Helix Player, while no specific Microsoft Windows or macOS versions are vulnerable.
What are the consequences of exploiting CVE-2009-4242?
Exploiting CVE-2009-4242 can allow attackers to execute arbitrary code on a victim's machine, compromising system security.