|
Some vulnerabilities have been reported in RealPlayer, which can be exploited by malicious people to compromise a vulnerable system. 1) An input validation error within the processing of Internet Video Recording (IVR) files can be exploited to cause a memory corruption when a specially crafted IVR file is viewed. 2) An unspecified error within the processing of IVR files can be exploited to write a NULL-byte to an arbitrary memory address via an overly long file name length value within a specially crafted IVR file. Successful exploitation potentially allows execution of arbitrary code e.g. when a user visits a malicious web page.
|