vendor:
RealPlayer
by:
Unknown
7.5
CVSS
HIGH
Buffer-Overflow
119
CWE
Product Name: RealPlayer
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: Unknown
CPE: a:realnetworks:realplayer
Platforms Tested:
Unknown
Buffer-Overflow Vulnerability in RichFX Basic Player ActiveX Control
The RichFX Basic Player ActiveX Control is prone to a buffer-overflow vulnerability due to inadequate boundary checks on user-supplied data. Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control, typically Internet Explorer. Failed exploit attempts may result in denial-of-service conditions.
Mitigation:
Apply the latest security updates from RealNetworks to ensure that the vulnerable ActiveX control is patched.