Lucene search

K
cveMitreCVE-2012-0923
HistoryFeb 08, 2012 - 3:55 p.m.

CVE-2012-0923

2012-02-0815:55:00
CWE-94
mitre
web.nvd.nist.gov
28
realnetworks
realplayer
cve-2012-0923
rv20 codec
remote code execution
arbitrary code
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.052

Percentile

93.1%

The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to execute arbitrary code via a crafted RV20 RealVideo video stream.

Affected configurations

Nvd
Node
realnetworksrealplayerMatch14.0.0
OR
realnetworksrealplayerMatch14.0.1
OR
realnetworksrealplayerMatch14.0.1.609
OR
realnetworksrealplayerMatch14.0.1.633
OR
realnetworksrealplayerMatch14.0.2
OR
realnetworksrealplayerMatch14.0.3
OR
realnetworksrealplayerMatch14.0.4
OR
realnetworksrealplayerMatch14.0.5
OR
realnetworksrealplayerMatch14.0.6
OR
realnetworksrealplayerMatch14.0.7
Node
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.0.1
OR
realnetworksrealplayerMatch11.0.2
OR
realnetworksrealplayerMatch11.0.2.1744
OR
realnetworksrealplayerMatch11.0.2.2315
OR
realnetworksrealplayerMatch11.0.3
OR
realnetworksrealplayerMatch11.0.4
OR
realnetworksrealplayerMatch11.0.5
OR
realnetworksrealplayerMatch11.1
OR
realnetworksrealplayerMatch11.1.3
OR
realnetworksrealplayerMatch11_build_6.0.14.748
Node
realnetworksrealplayerMatch15.0.0
OR
realnetworksrealplayerMatch15.0.1.13
Node
realnetworksrealplayer_spMatch1.0.0
OR
realnetworksrealplayer_spMatch1.0.1
OR
realnetworksrealplayer_spMatch1.0.2
OR
realnetworksrealplayer_spMatch1.0.5
OR
realnetworksrealplayer_spMatch1.1
OR
realnetworksrealplayer_spMatch1.1.1
OR
realnetworksrealplayer_spMatch1.1.2
OR
realnetworksrealplayer_spMatch1.1.3
OR
realnetworksrealplayer_spMatch1.1.4
OR
realnetworksrealplayer_spMatch1.1.5
VendorProductVersionCPE
realnetworksrealplayer14.0.0cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:*
realnetworksrealplayer14.0.1cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:*
realnetworksrealplayer14.0.1.609cpe:2.3:a:realnetworks:realplayer:14.0.1.609:*:*:*:*:*:*:*
realnetworksrealplayer14.0.1.633cpe:2.3:a:realnetworks:realplayer:14.0.1.633:*:*:*:*:*:*:*
realnetworksrealplayer14.0.2cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:*
realnetworksrealplayer14.0.3cpe:2.3:a:realnetworks:realplayer:14.0.3:*:*:*:*:*:*:*
realnetworksrealplayer14.0.4cpe:2.3:a:realnetworks:realplayer:14.0.4:*:*:*:*:*:*:*
realnetworksrealplayer14.0.5cpe:2.3:a:realnetworks:realplayer:14.0.5:*:*:*:*:*:*:*
realnetworksrealplayer14.0.6cpe:2.3:a:realnetworks:realplayer:14.0.6:*:*:*:*:*:*:*
realnetworksrealplayer14.0.7cpe:2.3:a:realnetworks:realplayer:14.0.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.052

Percentile

93.1%

Related for CVE-2012-0923