Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain Now Playing options on a downloaded file with a long filename.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Realone_player | Realnetworks | 2.0 (including) | 2.0 (including) |
Realplayer | Realnetworks | * | * |
Realplayer | Realnetworks | 6.0 (including) | 6.0 (including) |
Realplayer | Realnetworks | 7.0 (including) | 7.0 (including) |
Realplayer | Realnetworks | 8.0 (including) | 8.0 (including) |