First published: Thu Nov 24 2011(Updated: )
The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =12.0.0.1569 | |
RealPlayer | =8.0 | |
RealPlayer | <=12.0.0.1701 | |
RealPlayer | =10.0.0.305 | |
RealPlayer | =10.0.0.331 | |
RealPlayer | =10.0 | |
RealPlayer | =10.1 | |
RealPlayer | =7.0 | |
RealPlayer | =11.0 | |
RealPlayer | =10.0 | |
RealPlayer | <=14.0.7 | |
RealPlayer | =11.0.4 | |
RealPlayer | =4 | |
RealPlayer | =14.0.3 | |
RealPlayer | =5 | |
RealPlayer | =14.0.1 | |
RealPlayer | =12.0.0.1444 | |
RealPlayer | =11.0.2 | |
RealPlayer | =14.0.4 | |
RealPlayer | =11.0.3 | |
RealPlayer | =14.0.6 | |
RealPlayer | =11.0.2.2315 | |
RealPlayer | =11.0.5 | |
RealPlayer | =8 | |
RealPlayer | =11.0.2.1744 | |
RealPlayer | =7 | |
RealPlayer | =12.0.0.1548 | |
RealPlayer | =11.1.3 | |
RealPlayer | =10.5 | |
RealPlayer | =6 | |
RealPlayer | =11.1 | |
RealPlayer | =11.0.1 | |
RealPlayer | =11_build_6.0.14.748 | |
RealPlayer | =14.0.2 | |
RealPlayer | =14.0.1.609 | |
RealPlayer | =14.0.5 | |
RealPlayer | =14.0.1.633 | |
RealPlayer | =14.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4256 is considered critical due to its potential to allow remote code execution.
To fix CVE-2011-4256, upgrade RealPlayer to version 15.0.0 or later.
CVE-2011-4256 affects RealPlayer versions prior to 15.0.0 and includes various versions for Mac OS.
Yes, CVE-2011-4256 can be exploited remotely, allowing attackers to execute arbitrary code.
CVE-2011-4256 can be exploited through various unknown vectors, leading to arbitrary code execution.