Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2949

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2011-2949
Last Modified 05 Oct 2011 10:50:43
Published 18 Aug 2011 07:55:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-2949

Summary

Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via crafted ID3v2 tags in an MP3 file.

Vulnerable Systems

Application

  • Realnetworks Realplayer 11.0

  • Realnetworks Realplayer 11.1

  • Realnetworks Realplayer 14.0.0

  • Realnetworks Realplayer 14.0.1

  • Realnetworks Realplayer 14.0.2

  • Realnetworks Realplayer 14.0.3

  • Realnetworks Realplayer 14.0.4

  • Realnetworks Realplayer 14.0.5

  • Realnetworks Realplayer 2.0

  • Realnetworks Realplayer 2.1.2

  • Realnetworks Realplayer 2.1.3

  • Realnetworks Realplayer 2.1.4

  • Realnetworks Realplayer 2.1.5

  • Realnetworks Realplayer Sp 1.0.0

  • Realnetworks Realplayer Sp 1.0.1

  • Realnetworks Realplayer Sp 1.0.2

  • Realnetworks Realplayer Sp 1.0.5

  • Realnetworks Realplayer Sp 1.1

  • Realnetworks Realplayer Sp 1.1.1

  • Realnetworks Realplayer Sp 1.1.2

  • Realnetworks Realplayer Sp 1.1.3

  • Realnetworks Realplayer Sp 1.1.4

  • Realnetworks Realplayer Sp 1.1.5


References

MISC - http://zerodayinitiative.com/advisories/ZDI-11-267/

SECTRACK - 1025943

CONFIRM - http://service.real.com/realplayer/security/08162011_player/en/


Last Updated: 27 May 2016 10:57:13