CVE-2014-3113: Buffer Overflow
Published Jul 7, 2014
·Updated
Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.
Affected Software
2 affected components
RealNetworks RealPlayer<=17.0.8.22
RealNetworks RealPlayer=17.0.4.60
Event History
Jul 7, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3113?
CVE-2014-3113 is considered a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-3113?
To fix CVE-2014-3113, update RealPlayer to version 17.0.10.8 or later.
3
What types of attacks can exploit CVE-2014-3113?
CVE-2014-3113 can be exploited through specially crafted MP4 files that trigger buffer overflows.
4
Who is affected by CVE-2014-3113?
Users of RealPlayer versions prior to 17.0.10.8, including 17.0.4.60, are affected by CVE-2014-3113.
5
What are the symptoms of exploitation of CVE-2014-3113?
Exploitation of CVE-2014-3113 may result in unexpected crashes or arbitrary code execution within RealPlayer.