CVE-2010-5228: Medium severity realnetworks realplayer sp vulnerability
Published Sep 7, 2012
·Updated
Untrusted search path vulnerability in RealPlayer SP 1.1.5 12.0.0.879 allows local users to gain privileges via a Trojan horse rio500.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information.
Affected Software
1 affected component
RealNetworks RealPlayer SP=1.1.5
Event History
Sep 7, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-5228?
CVE-2010-5228 has a medium severity rating as it allows local users to gain privileges through a malicious DLL.
2
How do I fix CVE-2010-5228?
To fix CVE-2010-5228, ensure that you update RealPlayer SP to a newer, patched version.
3
Who is affected by CVE-2010-5228?
Users of RealPlayer SP version 1.1.5 are affected by CVE-2010-5228.
4
What type of vulnerability is CVE-2010-5228?
CVE-2010-5228 is classified as an untrusted search path vulnerability.
5
Can CVE-2010-5228 be exploited remotely?
No, CVE-2010-5228 requires local access to exploit the vulnerability.