CVE-2009-4248: Buffer Overflow
Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted RTSP SETPARAMETER request.
Other sources
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4248 to the following vulnerability:
Buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to have an unspecified impact via a crafted RTSP SETPARAMETER request.
References: http://service.real.com/realplayer/security/01192010player/en/ http://xforce.iss.net/xforce/xfdb/55801
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4248?
CVE-2009-4248 is classified as a high severity vulnerability due to its potential to execute arbitrary code.
How do I fix CVE-2009-4248?
To fix CVE-2009-4248, update to the latest version of RealPlayer or Helix Player provided by RealNetworks.
Which versions are affected by CVE-2009-4248?
CVE-2009-4248 affects RealPlayer versions 10, 10.5, and 11 up to 11.0.4 on various platforms.
What is the nature of the vulnerability in CVE-2009-4248?
CVE-2009-4248 is a buffer overflow vulnerability that occurs in the RTSPProtocol::HandleSetParameterRequest function.
Can CVE-2009-4248 be exploited remotely?
Yes, CVE-2009-4248 can be exploited remotely via malicious RTSP requests.