First published: Thu Dec 19 2013(Updated: )
Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a long string in the TRACKID element of an RMP file, a different vulnerability than CVE-2013-7260.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | =16.0.2.32 | |
RealPlayer | =16.0.3.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6877 is rated as critical due to the potential for remote code execution.
To fix CVE-2013-6877, upgrade to RealPlayer version 17.0.4.61 or later for Windows, or 12.0.1.1738 or later for Mac.
Users of RealNetworks RealPlayer versions 16.0.2.32 and 16.0.3.51 on both Windows and Mac are affected by CVE-2013-6877.
CVE-2013-6877 is a heap-based buffer overflow vulnerability.
Yes, CVE-2013-6877 allows remote attackers to execute arbitrary code, posing a significant security risk.