RealPlayer is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With specially crafted AAC raw_data_frame, a context-dependent attacker can potentially execute arbitrary code.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade RealPlayer to version 14.0.6 or higher and RealPlayer for Mac to version 12.0.0.1701 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.