CVE-2012-1904: Buffer Overflow
mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1904?
CVE-2012-1904 is classified as a high severity vulnerability that allows remote attackers to cause a denial of service through crafted MP4 files.
How do I fix CVE-2012-1904?
To mitigate CVE-2012-1904, users should update to a version of RealPlayer that is higher than 15.0.0 or apply available patches from RealNetworks.
What versions of RealPlayer are affected by CVE-2012-1904?
CVE-2012-1904 affects RealPlayer versions 15.0.0 and earlier, as well as various versions of RealPlayer SP up to 1.1.4.
What symptoms might indicate an exploit of CVE-2012-1904?
Exploitation of CVE-2012-1904 may lead to symptoms such as application crashes or unexpected behavior when playing certain MP4 files.
Who is at risk from CVE-2012-1904?
Any user running vulnerable versions of RealPlayer or RealNetworks RealPlayer SP is at risk from CVE-2012-1904.