CVE-2010-3747: Buffer Overflow
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during parsing of a CDDA URI, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and application crash) via a long URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3747?
CVE-2010-3747 is classified as a critical vulnerability due to its potential to allow remote code execution.
Which versions of RealPlayer are affected by CVE-2010-3747?
CVE-2010-3747 affects RealPlayer versions 11.0 through 11.1, RealPlayer SP versions 1.0 through 1.1.4, and RealPlayer Enterprise version 2.1.2.
How do I fix CVE-2010-3747?
To fix CVE-2010-3747, users should update to the latest version of RealPlayer provided by RealNetworks.
What type of attacks can CVE-2010-3747 enable?
CVE-2010-3747 can enable remote attackers to execute arbitrary code or cause a denial of service.
Is there any workaround for CVE-2010-3747?
Currently, the best mitigation for CVE-2010-3747 is to apply the available security updates provided by RealNetworks.