First published: Tue May 20 2014(Updated: )
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | <=16.0.3.51 | |
RealPlayer | =16.0.0 | |
RealPlayer | =16.0.0.282 | |
RealPlayer | =16.0.1.18 | |
RealPlayer | =16.0.2.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3444 has a high severity level due to its potential to allow remote code execution and application crashes.
To remediate CVE-2014-3444, upgrade to a later version of RealPlayer that is not affected by this vulnerability.
CVE-2014-3444 affects RealPlayer versions up to and including 16.0.3.51 and specific earlier releases.
CVE-2014-3444 enables remote attackers to execute arbitrary code through the exploitation of malformed .3gp files.
Yes, CVE-2014-3444 can also cause a denial of service by leading to application crashes from write access violations.