CVE-2009-4247: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4247 to the following vulnerability:
RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allow remote attackers to have an unspecified impact via a crafted ASM RuleBook, related to an "array overflow."
References: http://service.real.com/realplayer/security/01192010player/en/ http://xforce.iss.net/xforce/xfdb/55802
Other sources
Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an ASM RuleBook with a large number of rules, related to an "array overflow."
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4247?
CVE-2009-4247 has been rated as a high severity vulnerability due to a stack-based buffer overflow that can lead to remote code execution.
How do I fix CVE-2009-4247?
To mitigate CVE-2009-4247, users should update to the latest version of RealPlayer or Helix Player that addresses this vulnerability.
Which versions of RealPlayer are affected by CVE-2009-4247?
CVE-2009-4247 affects RealPlayer versions 10, 10.5, and 11, specifically from 6.0.12.1040 to 11.0.1.
Is macOS affected by CVE-2009-4247?
Yes, macOS versions of RealPlayer, including 10, 10.1, 11.0, and 11.0.1 are affected by CVE-2009-4247.
What impact can CVE-2009-4247 have on my system?
Exploitation of CVE-2009-4247 can allow an attacker to execute arbitrary code on the affected system, potentially compromising security.