RealNetworks.RealPlayer.ASMRulebook

NameRealNetworks.RealPlayer.ASMRulebook.Code.Execution
Release DateFeb 11, 2010
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a remote code-execution vulnerability in RealPlayer.

The vulnerability is caused by an error when the vulnerable software handles
malicious "ASMRuleBook" structures. It allows a remote attacker to execute
arbitrary code via sending a video file.
Affected ProductsRealNetworks RealPlayer
Recommended ActionsUpgrade to the latest version.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4241
Reference/shttp://www.securityfocus.com/bid/37880 (BugTraq)
http://www.zerodayinitiative.com/advisories/ZDI-10-005/
Reference: VID-18142