First published: Wed Feb 08 2012(Updated: )
rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =14.0.0 | |
RealPlayer | =14.0.1 | |
RealPlayer | =14.0.1.609 | |
RealPlayer | =14.0.1.633 | |
RealPlayer | =14.0.2 | |
RealPlayer | =14.0.3 | |
RealPlayer | =14.0.4 | |
RealPlayer | =14.0.5 | |
RealPlayer | =14.0.6 | |
RealPlayer | =14.0.7 | |
RealPlayer | =11.0 | |
RealPlayer | =11.0.1 | |
RealPlayer | =11.0.2 | |
RealPlayer | =11.0.2.1744 | |
RealPlayer | =11.0.2.2315 | |
RealPlayer | =11.0.3 | |
RealPlayer | =11.0.4 | |
RealPlayer | =11.0.5 | |
RealPlayer | =11.1 | |
RealPlayer | =11.1.3 | |
RealPlayer | =11_build_6.0.14.748 | |
RealPlayer | =15.0.0 | |
RealPlayer | =15.0.1.13 | |
RealNetworks RealPlayer SP | =1.0.0 | |
RealNetworks RealPlayer SP | =1.0.1 | |
RealNetworks RealPlayer SP | =1.0.2 | |
RealNetworks RealPlayer SP | =1.0.5 | |
RealNetworks RealPlayer SP | =1.1 | |
RealNetworks RealPlayer SP | =1.1.1 | |
RealNetworks RealPlayer SP | =1.1.2 | |
RealNetworks RealPlayer SP | =1.1.3 | |
RealNetworks RealPlayer SP | =1.1.4 | |
RealNetworks RealPlayer SP | =1.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0922 has a critical severity level that allows for remote code execution.
To mitigate CVE-2012-0922, you should update your RealPlayer to the latest version available.
CVE-2012-0922 affects RealPlayer versions 11.x, 14.x, and 15.x prior to 15.02.71.
CVE-2012-0922 is associated with a remote code execution exploit via crafted RMFF files.
Users of affected RealPlayer versions, especially those who handle RMFF files, are at risk from CVE-2012-0922.