CVE-2014-3444: Code Injection
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3444?
CVE-2014-3444 has a high severity level due to its potential to allow remote code execution and application crashes.
How do I fix CVE-2014-3444?
To remediate CVE-2014-3444, upgrade to a later version of RealPlayer that is not affected by this vulnerability.
What systems are affected by CVE-2014-3444?
CVE-2014-3444 affects RealPlayer versions up to and including 16.0.3.51 and specific earlier releases.
What type of attack does CVE-2014-3444 enable?
CVE-2014-3444 enables remote attackers to execute arbitrary code through the exploitation of malformed .3gp files.
Is CVE-2014-3444 a denial of service vulnerability?
Yes, CVE-2014-3444 can also cause a denial of service by leading to application crashes from write access violations.