RealPlayer SWF File Processing Heap Overflow Vulnerability

by arthack on 2008-07-29 18:58:52

Affected System:

Real Networks RealPlayer 10.5 Build 6.0.12.1483

Description:

BUGTRAQ ID: 30370

CVE(CAN) ID: CVE-2007-5400

RealPlayer is a popular multimedia player.

RealPlayer does not properly handle frames in Shockwave Flash (SWF) files. If a user is tricked into opening a malicious SWF file, it could trigger a heap overflow, allowing for arbitrary code execution.