Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file.
http://www.securityfocus.com/bid/61989
http://www.kb.cert.org/vuls/id/246524
http://service.real.com/realplayer/security/08232013_player/en/