RealPlayer for Windows < 16.0.1.18 MP4 Heap-Based Buffer Overflow

high Nessus Plugin ID 65630

Synopsis

A multimedia application on the remote Windows host is affected by a buffer overflow vulnerability.

Description

According to its build number, the installed version of RealPlayer on the remote Windows host is earlier than 16.0.1.18. It is, therefore, affected by a heap-based buffer overflow vulnerability related to handling malformed MP4 files that could lead to arbitrary code execution.

Solution

Upgrade to RealPlayer 16.0.1.18 or later.

See Also

http://service.real.com/realplayer/security/03152013_player/en/

Plugin Details

Severity: High

ID: 65630

File Name: realplayer_16_0_1_18.nasl

Version: 1.6

Type: local

Agent: windows

Family: Windows

Published: 3/20/2013

Updated: 7/25/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:realnetworks:realplayer

Required KB Items: SMB/RealPlayer/Product, SMB/RealPlayer/Build

Exploit Ease: No known exploits are available

Patch Publication Date: 3/15/2013

Vulnerability Publication Date: 3/15/2013

Reference Information

CVE: CVE-2013-1750

BID: 58539