First published: Wed Feb 03 2010(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2009-4257">CVE-2009-4257</a> to the following vulnerability: Heap-based buffer overflow in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths. References: <a href="http://service.real.com/realplayer/security/01192010_player/en/">http://service.real.com/realplayer/security/01192010_player/en/</a> <a href="http://www.zerodayinitiative.com/advisories/ZDI-10-007/">http://www.zerodayinitiative.com/advisories/ZDI-10-007/</a> <a href="http://www.securityfocus.com/archive/1/509105/100/0/threaded">http://www.securityfocus.com/archive/1/509105/100/0/threaded</a> <a href="http://xforce.iss.net/xforce/xfdb/55798">http://xforce.iss.net/xforce/xfdb/55798</a>
Affected Software | Affected Version | How to fix |
---|---|---|
RealPlayer | >=6.0.12.1040<6.0.12.1741>=11.0.0<11.0.4 | |
RealPlayer | ||
RealPlayer | ||
RealNetworks Helix Player Linux | >=10.x<11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-561309 is considered high due to the heap-based buffer overflow vulnerability that can be exploited.
To fix REDHAT-BUG-561309, it is recommended to update RealPlayer to a version that is not affected by this vulnerability.
REDHAT-BUG-561309 affects RealPlayer versions 6.0.12.1040 through 6.0.12.1741 and versions up to 11.0.4.
Yes, RealPlayer Enterprise is considered vulnerable under REDHAT-BUG-561309 due to its association with affected RealPlayer versions.
CVE-2009-4257, associated with REDHAT-BUG-561309, highlights the specific heap-based buffer overflow vulnerability found in RealNetworks' software.