Lucene search

K
cveMitreCVE-2009-4248
HistoryJan 25, 2010 - 7:30 p.m.

CVE-2009-4248

2010-01-2519:30:01
CWE-119
mitre
web.nvd.nist.gov
41
cve-2009-4248
buffer overflow
rtspprotocol
realnetworks
realplayer
denial of service
dos
remote code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.101

Percentile

95.0%

Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted RTSP SET_PARAMETER request.

Affected configurations

Nvd
Node
realnetworksrealplayerMatch10.0
OR
realnetworksrealplayerMatch10.5
OR
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.0.1
OR
realnetworksrealplayerMatch11.0.2
OR
realnetworksrealplayerMatch11.0.3
OR
realnetworksrealplayerMatch11.0.4
OR
realnetworksrealplayerMatch11.0.5
OR
realnetworksrealplayer_enterprise
OR
realnetworksrealplayer_spMatch1.0.0
OR
realnetworksrealplayer_spMatch1.0.1
AND
microsoftwindows
Node
realnetworksrealplayerMatch10.0
OR
realnetworksrealplayerMatch10.1
OR
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.0.1
AND
applemac_os_x
Node
realnetworkshelix_playerMatch10.0
OR
realnetworkshelix_playerMatch11.0.0
OR
realnetworkshelix_playerMatch11.0.1
OR
realnetworksrealplayerMatch10.0linux
OR
realnetworksrealplayerMatch11.0.0linux
OR
realnetworksrealplayerMatch11.0.1linux
VendorProductVersionCPE
realnetworksrealplayer10.0cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
realnetworksrealplayer10.5cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*
realnetworksrealplayer11.0cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*
realnetworksrealplayer11.0.1cpe:2.3:a:realnetworks:realplayer:11.0.1:*:*:*:*:*:*:*
realnetworksrealplayer11.0.2cpe:2.3:a:realnetworks:realplayer:11.0.2:*:*:*:*:*:*:*
realnetworksrealplayer11.0.3cpe:2.3:a:realnetworks:realplayer:11.0.3:*:*:*:*:*:*:*
realnetworksrealplayer11.0.4cpe:2.3:a:realnetworks:realplayer:11.0.4:*:*:*:*:*:*:*
realnetworksrealplayer11.0.5cpe:2.3:a:realnetworks:realplayer:11.0.5:*:*:*:*:*:*:*
realnetworksrealplayer_enterprise*cpe:2.3:a:realnetworks:realplayer_enterprise:*:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.0cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.101

Percentile

95.0%