CVE-2013-7260: Buffer Overflow
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RealNetworks RealPlayer (Windows)to a version that resolves this vulnerability.Fixed in 17.0.4.61 - Upgrade
Upgrade
RealNetworks RealPlayer (Mac)to a version that resolves this vulnerability.Fixed in 12.0.1.1738
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7260?
CVE-2013-7260 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2013-7260?
To fix CVE-2013-7260, users should update RealPlayer to the latest version available, at least version 17.0.4.61 for Windows or 12.0.1.1738 for Mac.
What systems are affected by CVE-2013-7260?
CVE-2013-7260 affects RealPlayer versions prior to 17.0.4.61 on Windows and prior to 12.0.1.1738 on macOS.
What type of vulnerability is CVE-2013-7260?
CVE-2013-7260 is a stack-based buffer overflow vulnerability.
Who can exploit CVE-2013-7260?
CVE-2013-7260 can be exploited by remote attackers, allowing them to execute arbitrary code on the affected systems.