CVE-2011-2949

high

Description

Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via crafted ID3v2 tags in an MP3 file.

References

http://zerodayinitiative.com/advisories/ZDI-11-267/

http://www.securitytracker.com/id?1025943

http://service.real.com/realplayer/security/08162011_player/en/

Details

Source: Mitre, NVD

Published: 2011-08-18

Updated: 2011-10-06

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High