CVE-2009-4242

EUVD-2009-4211
Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/gifcodec.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via a GIF file with crafted chunk sizes that trigger improper memory allocation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
realnetworksrealplayer
10.0
realnetworksrealplayer
10.5
realnetworksrealplayer
11.0
realnetworksrealplayer
11.0.1
realnetworksrealplayer
11.0.2
realnetworksrealplayer
11.0.3
realnetworksrealplayer
11.0.4
realnetworksrealplayer
11.0.5
realnetworksrealplayer_enterprise
*
realnetworksrealplayer_sp
1.0.0
realnetworksrealplayer_sp
1.0.1
realnetworksrealplayer
10.0
realnetworksrealplayer
10.1
realnetworksrealplayer
11.0
realnetworksrealplayer
11.0.1
realnetworkshelix_player
10.0
realnetworkshelix_player
11.0.0
realnetworkshelix_player
11.0.1
realnetworksrealplayer
10.0
realnetworksrealplayer
11.0.0
realnetworksrealplayer
11.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
realplay
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
realplayer
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
References