CVE-2012-2408: Buffer Overflow
The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2408?
CVE-2012-2408 has a severity rating that indicates it can cause a denial of service due to heap memory corruption.
How do I fix CVE-2012-2408?
To fix CVE-2012-2408, you should upgrade to the latest version of RealPlayer that addresses this vulnerability.
What software is affected by CVE-2012-2408?
CVE-2012-2408 affects several versions of RealPlayer up to and including version 15.0.5.109 and specific versions of RealNetworks RealPlayer SP.
What type of attack can exploit CVE-2012-2408?
CVE-2012-2408 can be exploited by attackers through a crafted AAC file designed to trigger heap memory corruption.
Are there any known exploits for CVE-2012-2408?
There are no specific known exploits publicly available for CVE-2012-2408, but the vulnerability poses a risk of denial of service.