CVE-2009-4245 Information
Description
Heap-based buffer overflow in RealNetworks RealPlayer 10 RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741 RealPlayer 11 11.0.0 through 11.0.4 RealPlayer Enterprise Mac RealPlayer 10 and 10.1 Linux RealPlayer 10 and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file related to gifcodec.cpp and gifimage.cpp.
Reference
http://lists.helixcommunity.org/pipermail/datatype-cvs/2008-July/008455.html http://osvdb.org/61969 http://secunia.com/advisories/38218 http://secunia.com/advisories/38450 http://securitytracker.com/id?1023489 http://service.real.com/realplayer/security/01192010_player/en/ http://www.redhat.com/support/errata/RHSA-2010-0094.html http://www.securityfocus.com/bid/37880 http://www.vupen.com/english/advisories/2010/0178 https://bugzilla.redhat.com/show_bug.cgi?id=561441 https://exchange.xforce.ibmcloud.com/vulnerabilities/55800 https://helixcommunity.org/viewcvs/datatype/image/gif/common/gifcodec.cpp?view=logrev1.7 https://helixcommunity.org/viewcvs/datatype/image/gif/common/gifimage.cpp?view=logrev1.6 https://helixcommunity.org/viewcvs/datatype/image/gif/common/pub/gifcodec.h?view=logrev1.5 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A9998
Share on: