[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

95906

 
 

909

 
 

77986

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2010-4378

Date: (C)2010-12-14   (M)2015-12-16
 
CVSS Score: 9.3Access Vector: NETWORK
Exploitability Subscore: 8.6Access Complexity: MEDIUM
Impact Subscore: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE











The drv2.dll (aka RV20 decompression) module in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, RealPlayer Enterprise 2.1.2 and 2.1.3, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted value of an unspecified length field in an RV20 video stream.

Reference:
SECTRACK-1024861
RHSA-2010:0981
http://service.real.com/realplayer/security/12102010_player/en/
http://www.zerodayinitiative.com/advisories/ZDI-10-274

CPE    20
cpe:/a:realnetworks:realplayer:2.1.2::enterprise
cpe:/a:realnetworks:realplayer:2.1.3::enterprise
cpe:/a:realnetworks:realplayer:11.0.2.1744
cpe:/a:realnetworks:realplayer_sp:1.1.5
...
CWE    1
CWE-119
OVAL    2
oval:org.secpod.oval:def:201570
oval:org.secpod.oval:def:201565

© 2013 SecPod Technologies