Thursday, September 2, 2010

RealNetworks RealPlayer: Malformed IVR Object Index Code Execution Vulnerability

Users of RealNetworks RealPlayer please be advised of a Malformed IVR Object Index Code Execution vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
ZDI-10-166: RealNetworks RealPlayer Malformed IVR Object Index Code Execution Vulnerability
-- Affected Products:

RealNetworks RealPlayer
-- Vulnerability Details:

This vulnerability allows attackers to execute arbitrary code on

vulnerable installations of RealNetworks RealPlayer. User interaction is

required to exploit this vulnerability in that the target must visit a

malicious page or open a malicious file.


Read more at www.criticalwatch.com
 

No comments:

Post a Comment