This application requires Javascript for optimal performance.

RealNetworks.RealPlayer.ASMRulebook.Code.Execution

Release Date

Feb 11, 2010

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a remote code-execution vulnerability in RealPlayer.

The vulnerability is caused by an error when the vulnerable software handles
malicious "ASMRuleBook" structures. It allows a remote attacker to execute
arbitrary code via sending a video file.

Affected Products

RealNetworks RealPlayer

Recommended Actions

Upgrade to the latest version.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4241

Reference/s

http://www.zerodayinitiative.com/advisories/ZDI-10-005/
http://www.securityfocus.com/bid/37880 (BugTraq)

Reference: VID-18142