This application requires Javascript for optimal performance.

RealNetworks.RealPlayer.SMIL.GetAtom.Code.Execution

Release Date

Feb 11, 2010

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a code-execution vulnerability in RealNetworks RealPlayer.

The vulnerability is caused by an error when the vulnerable software handles
malicious RDT packets. It allows a remote attacker to execute
arbitrary code via sending crafted packets.

Affected Products

RealNetworks RealPlayer

Recommended Actions

Upgrade to the latest version.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4257

Reference/s

http://www.zerodayinitiative.com/advisories/ZDI-10-007/
http://www.securityfocus.com/bid/37880 (BugTraq)

Reference: VID-18144