CVE-2011-2951

critical

Description

Buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.0.0.1569 allows remote attackers to execute arbitrary code via a crafted raw_data_frame field in an AAC file.

References

http://zerodayinitiative.com/advisories/ZDI-11-266/

http://www.securitytracker.com/id?1025943

http://service.real.com/realplayer/security/08162011_player/en/

Details

Source: Mitre, NVD

Published: 2011-08-18

Updated: 2011-10-06

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical