First published: Wed Feb 08 2012(Updated: )
The ATRAC codec in RealNetworks RealPlayer 11.x and 14.x through 14.0.7, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.x before 12.0.0.1703 does not properly decode samples, which allows remote attackers to execute arbitrary code via a crafted ATRAC audio file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =14.0.0 | |
RealPlayer | =14.0.1 | |
RealPlayer | =14.0.1.609 | |
RealPlayer | =14.0.1.633 | |
RealPlayer | =14.0.2 | |
RealPlayer | =14.0.3 | |
RealPlayer | =14.0.4 | |
RealPlayer | =14.0.5 | |
RealPlayer | =14.0.6 | |
RealPlayer | =14.0.7 | |
RealPlayer | =11.0 | |
RealPlayer | =11.0.1 | |
RealPlayer | =11.0.2 | |
RealPlayer | =11.0.2.1744 | |
RealPlayer | =11.0.2.2315 | |
RealPlayer | =11.0.3 | |
RealPlayer | =11.0.4 | |
RealPlayer | =11.0.5 | |
RealPlayer | =11.1 | |
RealPlayer | =11.1.3 | |
RealPlayer | =11_build_6.0.14.748 | |
RealNetworks RealPlayer SP | =1.0.0 | |
RealNetworks RealPlayer SP | =1.0.1 | |
RealNetworks RealPlayer SP | =1.0.2 | |
RealNetworks RealPlayer SP | =1.0.5 | |
RealNetworks RealPlayer SP | =1.1 | |
RealNetworks RealPlayer SP | =1.1.1 | |
RealNetworks RealPlayer SP | =1.1.2 | |
RealNetworks RealPlayer SP | =1.1.3 | |
RealNetworks RealPlayer SP | =1.1.4 | |
RealNetworks RealPlayer SP | =1.1.5 | |
RealPlayer | =12.0.0.1569 | |
RealPlayer | =12.0.0.1701 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0928 has a high severity level due to its potential to allow remote code execution.
To fix CVE-2012-0928, update your RealPlayer to the latest version provided by RealNetworks.
CVE-2012-0928 affects RealPlayer versions 11.x and 14.x, including specific versions 11.0 through 11.1.5 and 14.0.0 through 14.0.7.
Exploiting CVE-2012-0928 can allow attackers to execute arbitrary code on the user's system.
Users of affected versions of RealPlayer who play crafted ATRAC audio files are at risk from CVE-2012-0928.