HIGH
HelixPlayer multiple flaws (CVE-2010-2997, CVE-2010-4375, CVE-2010-4378, CVE-2010-4379, CVE-2010-4382, CVE-2010-4383, CVE-2010-4385, CVE-2010-4386, CVE-2010-4392, CVE-2010-4376)
Published Dec 14, 2010
9.3
HIGHCVSS 2.0
EPSS 3.13%
Description
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 12.0.0.1444, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to have an unspecified impact via a crafted RA5 file.
Affected products
No data.
Configuration 1
OR
- 11.0
- 11.0.1
- 11.0.2
- 11.0.3
- 11.0.4
- 11.0.5
- 11.1
Configuration 2
OR
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.5
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
Configuration 3
AND
OR
- 11.0
- 11.0.1
- 11.0.2
- 11.0.3
- 11.0.4
- 11.0.5
- 11.1
- 12.0.0.1444
Configuration 4
AND
- 11.0.2.1744
Running on/with
- n/a
Configuration 5
- 2.1.2
No data.
Red Hat Enterprise Linux 4
HelixPlayer-1:1.0.6-3.el4_8.1
Fixed · RHSA-2010:0981
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | HelixPlayer-1:1.0.6-3.el4_8.1 | Fixed | RHSA-2010:0981 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://service.real.com/realplayer/security/12102010_player/en/ x_refsource_CONFIRMVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0981.html vendor-advisoryx_refsource_REDHAT
- http://www.securitytracker.com/id?1024861 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2010-4383 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=662772 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-4352 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-4383
- https://www.cve.org/CVERecord?id=CVE-2010-4383
| Link | Providers | Tags |
|---|---|---|
| http://service.real.com/realplayer/security/12102010_player/en/ | x_refsource_CONFIRMVendor Advisory | |
| http://www.redhat.com/support/errata/RHSA-2010-0981.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.securitytracker.com/id?1024861 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2010-4383 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=662772 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-4352 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-4383 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-4383 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 14, 2010
Updated Aug 7, 2024
Reserved Dec 2, 2010
Link CVE-2010-4383
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-4352 Assigner mitre
Published Dec 14, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-4352