CVE-2010-3750: Input Validation
rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, which allows remote attackers to execute arbitrary code via crafted Name Value Property (NVP) elements in logical streams in a media file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3750?
CVE-2010-3750 has been classified as a critical vulnerability that can lead to arbitrary code execution.
How do I fix CVE-2010-3750?
To fix CVE-2010-3750, update your RealPlayer to the latest version provided by RealNetworks.
Which versions of RealPlayer are affected by CVE-2010-3750?
CVE-2010-3750 affects RealPlayer versions 11.0 to 11.1, RealPlayer SP versions 1.0 to 1.1.4, and RealPlayer Enterprise version 2.1.2.
What are the risks of leaving CVE-2010-3750 unpatched?
Leaving CVE-2010-3750 unpatched exposes your system to potential arbitrary code execution by remote attackers.
Is there any temporary workaround for CVE-2010-3750?
Currently, the best workaround for CVE-2010-3750 is to disable or uninstall RealPlayer until the software is updated.