CVE-2010-2999: Integer Overflow
Integer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.0.1, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed MLLT atom in an AAC file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2010-2999?
CVE-2010-2999 is a vulnerability in RealNetworks RealPlayer that allows remote attackers to execute arbitrary code or cause a denial of service due to an integer overflow involving a malformed MLLT atom.
What versions of RealPlayer are affected by CVE-2010-2999?
CVE-2010-2999 affects RealPlayer versions 11.0 through 11.1, RealPlayer SP 1.0 through 1.0.1, and specific builds of Mac and Linux RealPlayer.
How can I mitigate the risk of CVE-2010-2999?
To mitigate the risk of CVE-2010-2999, users should update RealPlayer to the latest version or apply any security patches provided by RealNetworks.
What types of attacks can be executed due to CVE-2010-2999?
CVE-2010-2999 can lead to arbitrary code execution or heap memory corruption, potentially resulting in a denial of service.
Is CVE-2010-2999 still a risk for users of RealPlayer?
Users of RealPlayer should verify they are using an updated version, as outdated versions may still be vulnerable to CVE-2010-2999.