Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2010-02-01.3

iDefense Security Advisory 02.01.10 – Remote exploitation of an integer overflow vulnerability in Real Networks Inc.’s RealPlayer version 11 could allow an attacker to execute arbitrary code. iDefense Labs has confirmed the existence of an integer overflow issue within RealPlayer when handling compressed GIF files. The vulnerability occurs in the CGIFCodec::InitDecompress() function, which does not properly validate a field in the GIF file before using it in an arithmetic operation that calculates the size of a heap buffer. This issue leads to heap corruption, which can result in the execution of arbitrary code. iDefense confirmed RealPlayer version 11 is vulnerable to this issue.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/85843/02.01.10-3.txt

Source: https://packetstormsecurity.com/files/85843/iDEFENSE-Security-Advisory-2010-02-01.3.html

Related posts
Advisories

Secunia Security Advisory 16074

Advisories

Secunia Security Advisory 19116

Advisories

Secunia Security Advisory 21833

Advisories

Ubuntu Security Notice 451-1