Description
Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain "Now Playing" options on a downloaded file with a long filename.
Affected products
- RealNetworks / realone_player2.0 – 2.0
- RealNetworks / realplayer
- RealNetworks / realplayer6.0 – 6.0
- RealNetworks / realplayer7.0 – 7.0
- RealNetworks / realplayer8.0 – 8.0