First published: Tue Dec 14 2010(Updated: )
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, and Mac RealPlayer 11.0 through 12.0.0.1444 allows remote attackers to have an unspecified impact via a crafted AAC file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =11.0 | |
RealPlayer | =11.0.4 | |
RealPlayer | =11.0.2 | |
RealPlayer | =11.0.3 | |
RealPlayer | =11.0.5 | |
RealPlayer | =11.1 | |
RealPlayer | =11.0.1 | |
RealNetworks RealPlayer SP | =1.0.1 | |
RealNetworks RealPlayer SP | =1.1.3 | |
RealNetworks RealPlayer SP | =1.0.0 | |
RealNetworks RealPlayer SP | =1.0.2 | |
RealNetworks RealPlayer SP | =1.1 | |
RealNetworks RealPlayer SP | =1.1.2 | |
RealNetworks RealPlayer SP | =1.1.4 | |
RealNetworks RealPlayer SP | =1.1.1 | |
RealNetworks RealPlayer SP | =1.0.5 | |
RealPlayer | =2.1.2 | |
RealPlayer | =1.0.0 | |
RealPlayer | =1.0.1 | |
RealPlayer | =1.0.2 | |
RealPlayer | =1.0.5 | |
RealPlayer | =1.1 | |
RealPlayer | =1.1.1 | |
RealPlayer | =1.1.2 | |
RealPlayer | =1.1.3 | |
RealPlayer | =1.1.4 | |
RealPlayer | =12.0.0.1444 | |
macOS Yosemite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4381 is considered a critical vulnerability due to the potential for remote code execution via a crafted AAC file.
To fix CVE-2010-4381, users should update their RealPlayer to a version that addresses this vulnerability as specified by RealNetworks.
CVE-2010-4381 affects RealPlayer versions from 11.0 to 11.1, RealPlayer SP versions 1.0 to 1.1.4, and certain versions of RealPlayer Enterprise and Mac RealPlayer.
Yes, CVE-2010-4381 can be exploited remotely by attackers using a specially crafted AAC file.
CVE-2010-4381 is a heap-based buffer overflow vulnerability.