RULE(RULE ID:317330)

Rule General Information
Release Date: 2017-04-19
Rule Name: FILE-OTHER Realnetworks Realplayer Malformed RM File Heap Overflow Vulnerability (CVE-2004-1481)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.
Impact: A heap overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service.
Affected OS: Windows
Reference: SecurityFocusBID:11309
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.service.real.com/help/faq/security/040928_player/DE/