RealPlayer 3GP file handling memory corruption
Publish Date: 21 lipca 2015
Severity: : Critical
Advisory Date: 21 lipca 2015
DESCRIPTION
A code execution vulnerability exists in RealNetworks RealPlayer. The vulnerability is caused by memory corruption while parsing 3gp video files.
An attacker can exploit these vulnerabilities by enticing a user to open a specially crafted .3gp file, with the affected application. Successful exploitation can result in arbitrary code execution in the context of the currently logged-in user.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1005229
Trend Micro Deep Security DPI Rule Name: 1005229 - RealPlayer 3GP File Handling Memory Corruption Vulnerability
AFFECTED SOFTWARE AND VERSION:
- RealPlayer