This application requires Javascript for optimal performance.

RealNetworks.RealPlayer.Skin.Parsing.Code.Execution

Release Date

Feb 11, 2010

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a remote code-execution vulnerability in RealNetworks Realplayer.

The vulnerability is caused by an error when the vulnerable software handles
a malicious skin file. It allows a remote attacker to execute arbitrary code via sending a crafted file.

Affected Products

RealNetworks RealPlayer 11 and earlier versions

Recommended Actions

Upgrade to the latest version.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4246

Reference/s

http://www.zerodayinitiative.com/advisories/ZDI-10-010/
http://www.securityfocus.com/bid/37880 (BugTraq)

Reference: VID-18147