CVE-2010-4397: Integer Overflow
Integer overflow in the pnen3260.dll module in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.1, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via a crafted TIT2 atom in an AAC file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4397?
CVE-2010-4397 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2010-4397?
To mitigate CVE-2010-4397, users should update RealPlayer to the latest patched version provided by RealNetworks.
Which versions of RealPlayer are affected by CVE-2010-4397?
CVE-2010-4397 affects RealPlayer versions 11.0 through 11.1, and RealPlayer SP versions 1.0 through 1.1.1.
Can CVE-2010-4397 be exploited remotely?
Yes, CVE-2010-4397 can be exploited remotely through a crafted AAC file containing a malicious TIT2 atom.
What operating systems are vulnerable to CVE-2010-4397?
CVE-2010-4397 impacts RealPlayer on Windows, Mac, and Linux systems.