First published: Thu Aug 18 2011(Updated: )
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via crafted ID3v2 tags in an MP3 file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =11.0 | |
RealPlayer | =11.1 | |
RealPlayer | =14.0.3 | |
RealPlayer | =14.0.1 | |
RealPlayer | =14.0.4 | |
RealPlayer | =14.0.2 | |
RealPlayer | =14.0.5 | |
RealPlayer | =14.0.0 | |
RealNetworks RealPlayer SP | =1.0.1 | |
RealNetworks RealPlayer SP | =1.1.5 | |
RealNetworks RealPlayer SP | =1.1.3 | |
RealNetworks RealPlayer SP | =1.0.0 | |
RealNetworks RealPlayer SP | =1.0.2 | |
RealNetworks RealPlayer SP | =1.1 | |
RealNetworks RealPlayer SP | =1.1.2 | |
RealNetworks RealPlayer SP | =1.1.4 | |
RealNetworks RealPlayer SP | =1.1.1 | |
RealNetworks RealPlayer SP | =1.0.5 | |
RealPlayer | =2.1.5 | |
RealPlayer | =2.1.3 | |
RealPlayer | =2.1.2 | |
RealPlayer | =2.0 | |
RealPlayer | =2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2949 is rated with a high severity due to its potential for remote code execution.
To fix CVE-2011-2949, ensure that RealPlayer and RealPlayer SP are updated to the latest versions released by RealNetworks.
CVE-2011-2949 affects RealPlayer versions 11.0 through 11.1 and 14.0.0 through 14.0.5.
Yes, RealNetworks RealPlayer SP versions 1.0 through 1.1.5 are also vulnerable to CVE-2011-2949.
Yes, CVE-2011-2949 can be exploited using crafted ID3v2 tags in MP3 files.