| Release Date: | 2010-01-25 | |
| Impact: | Critical | What is this? |
Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an ASM RuleBook with a large number of rules, related to an array overflow.
See more information about CVE-2009-4247 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
| Base Score: | 9.3 |
| Vector String: | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| Version: | 2.0 |
| Attack Vector: | Network |
| Attack Complexity: | Medium |
| Authentication: | None |
| Confidentiality Impact: | Complete |
| Integrity Impact: | Complete |
| Availability Impact: | Complete |
| Platform | Errata | Release Date |
| Oracle Enterprise Linux version 4 (HelixPlayer) | ELSA-2010-0094 | 2010-02-09 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: