Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain Now Playing options on a downloaded file with a long filename.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Realone_player | Realnetworks | 2.0 (including) | 2.0 (including) |
| Realplayer | Realnetworks | * | * |
| Realplayer | Realnetworks | 6.0 (including) | 6.0 (including) |
| Realplayer | Realnetworks | 7.0 (including) | 7.0 (including) |
| Realplayer | Realnetworks | 8.0 (including) | 8.0 (including) |