HIGH
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content
Published Aug 30, 2010
9.3
HIGHCVSS 2.0
EPSS 5.72%
Description
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content.
Affected products
No data.
Configuration 1
AND
OR
- 11.0
- 11.1
Configuration 2
AND
OR
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.5
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://secunia.com/advisories/41096 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/41154 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/secunia_research/2010-8/ x_refsource_MISCVendor Advisory
- http://service.real.com/realplayer/security/08262010_player/en/ x_refsource_CONFIRMVendor Advisory
- http://www.securitytracker.com/id?1024370 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2010/2216 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0152 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61422 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6807 vdb-entrysignaturex_refsource_OVAL
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/41096 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/41154 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/secunia_research/2010-8/ | x_refsource_MISCVendor Advisory | |
| http://service.real.com/realplayer/security/08262010_player/en/ | x_refsource_CONFIRMVendor Advisory | |
| http://www.securitytracker.com/id?1024370 | vdb-entryx_refsource_SECTRACK | |
| http://www.vupen.com/english/advisories/2010/2216 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0152 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/61422 | vdb-entryx_refsource_XF | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6807 | vdb-entrysignaturex_refsource_OVAL |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Aug 30, 2010
Updated Aug 7, 2024
Reserved Jan 4, 2010
Link CVE-2010-0120
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-0152 Assigner flexera
Published Aug 30, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-0152