CVE-2009-4245: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4245 to the following vulnerability:
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to have an unspecified impact via a compressed GIF file.
References: http://service.real.com/realplayer/security/01192010player/en/ http://xforce.iss.net/xforce/xfdb/55800
Other sources
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4245?
CVE-2009-4245 has been classified as a high severity vulnerability due to the potential for remote attackers to cause denial of service.
How do I fix CVE-2009-4245?
To fix CVE-2009-4245, it is recommended to update to the latest version of RealPlayer or apply any available security patches.
What software is affected by CVE-2009-4245?
CVE-2009-4245 affects multiple versions of RealPlayer 10 and 11, as well as Helix Player 10.x.
Can CVE-2009-4245 be exploited remotely?
Yes, CVE-2009-4245 can be exploited remotely, allowing attackers to execute a denial of service attack.
What type of vulnerability is CVE-2009-4245?
CVE-2009-4245 is a heap-based buffer overflow vulnerability.