First published: Tue Dec 14 2010(Updated: )
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, Mac RealPlayer 11.0 through 12.0.0.1444, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code by specifying many subbands in cook audio codec information in a Real Audio file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =11.0 | |
RealPlayer | =11.0.4 | |
RealPlayer | =11.0.2 | |
RealPlayer | =11.0.3 | |
RealPlayer | =11.0.5 | |
RealPlayer | =11.1 | |
RealPlayer | =11.0.1 | |
RealNetworks RealPlayer SP | =1.0.1 | |
RealNetworks RealPlayer SP | =1.1.5 | |
RealNetworks RealPlayer SP | =1.1.3 | |
RealNetworks RealPlayer SP | =1.0.0 | |
RealNetworks RealPlayer SP | =1.0.2 | |
RealNetworks RealPlayer SP | =1.1 | |
RealNetworks RealPlayer SP | =1.1.2 | |
RealNetworks RealPlayer SP | =1.1.4 | |
RealNetworks RealPlayer SP | =1.1.1 | |
RealNetworks RealPlayer SP | =1.0.5 | |
RealPlayer | =1.0.0 | |
RealPlayer | =1.0.1 | |
RealPlayer | =1.0.2 | |
RealPlayer | =1.0.5 | |
RealPlayer | =1.1 | |
RealPlayer | =1.1.1 | |
RealPlayer | =1.1.2 | |
RealPlayer | =1.1.3 | |
RealPlayer | =1.1.4 | |
RealPlayer | =1.1.5 | |
RealPlayer | =12.0.0.1444 | |
macOS Yosemite | ||
RealPlayer | =11.0.2.1744 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4377 has a CVSS score that indicates a high severity due to the potential for remote code execution.
To fix CVE-2010-4377, users should update their RealPlayer application to the latest version provided by RealNetworks.
CVE-2010-4377 affects RealPlayer versions 11.0 through 11.1 and RealPlayer SP versions 1.0 through 1.1.5.
Yes, CVE-2010-4377 allows remote attackers to execute arbitrary code, potentially leading to unauthorized access.
CVE-2010-4377 impacts RealPlayer on Windows, macOS, and Linux systems.