REDHAT-BUG-561338: Realplayer vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4247 to the following vulnerability:
RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allow remote attackers to have an unspecified impact via a crafted ASM RuleBook, related to an "array overflow."
References: http://service.real.com/realplayer/security/01192010player/en/ http://xforce.iss.net/xforce/xfdb/55802
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-561338?
The severity of REDHAT-BUG-561338 is classified as moderate.
How do I fix REDHAT-BUG-561338?
To fix REDHAT-BUG-561338, update RealNetworks RealPlayer to the latest version available.
Which versions of RealPlayer are affected by REDHAT-BUG-561338?
Affected versions include RealPlayer 10, 10.5, and 11.x, as well as specific versions within those ranges.
What is the vulnerability type of REDHAT-BUG-561338?
REDHAT-BUG-561338 is a vulnerability related to remote code execution.
Is Helix Player also affected by REDHAT-BUG-561338?
Yes, Helix Player versions between 10.0 and 11.0.1 are also affected by REDHAT-BUG-561338.