RealNetworks.RealPlayer.Skin.Parsing

NameRealNetworks.RealPlayer.Skin.Parsing.Code.Execution
Release DateFeb 11, 2010
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a remote code-execution vulnerability in RealNetworks Realplayer.

The vulnerability is caused by an error when the vulnerable software handles
a malicious skin file. It allows a remote attacker to execute arbitrary code via sending a crafted file.
Affected ProductsRealNetworks RealPlayer 11 and earlier versions
Recommended ActionsUpgrade to the latest version.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4246
Reference/shttp://www.securityfocus.com/bid/37880 (BugTraq)
http://www.zerodayinitiative.com/advisories/ZDI-10-010/
Reference: VID-18147